CVE-2026-107709: CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Bower Decompress-Zip decompress-zip
Description
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.
CVSS v3.1
Score 7.8high
Affected software
Bower Decompress-Zip
decompress-zip
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in Bower decompress-zip (<=0.3.3) arises from insufficient validation of ZIP archive entry paths in lib/decompress-zip.js. Specifically, crafted ZIP archives containing entries that resolve to directories outside the intended extraction folder can cause files to be written to prefix-sibling directories. This path traversal (CWE-22) can be exploited to overwrite arbitrary files, which may lead to application compromise or remote code execution depending on the target environment's writable paths.
Potential Impact
Successful exploitation allows an attacker to overwrite arbitrary files outside the intended extraction directory. This can result in application compromise or remote code execution if critical files are overwritten and the environment permits execution of malicious code. The impact depends on the writable sibling directories accessible during extraction.
Mitigation Recommendations
No official patch or fix is currently documented. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, avoid extracting untrusted ZIP archives with decompress-zip versions up to 0.3.3 or implement manual path validation to prevent traversal outside the intended directory.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- certcc
- Date Reserved
- 2026-10-08T16:57:51.188Z
- State
- PUBLISHED
Threat ID: 6ac7d49a2cdf04f6562c68b0
Added to database: 10/08/2026, 17:36:26 UTC
Last enriched: 10/08/2026, 17:48:42 UTC
Last updated: 10/09/2026, 06:48:08 UTC
Views: 8
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.