PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-107709 Bower Decompress-Zip CVE debrief

A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability improperly validates archive entry paths during ZIP extraction, allowing crafted ZIP archives to write files outside the intended extraction directory. This could lead to arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. Defenders should assess exposure and prioritize verification and potential upgrades.

Vendor
Bower Decompress-Zip
Product
decompress-zip
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for systems using Bower decompress-zip should assess exposure and prioritize verification and potential upgrades. This includes reviewing system configurations, assessing the risk of arbitrary file overwrite, application compromise, or remote code execution, and considering upgrades to a patched version of decompress-zip.

Why it matters

Defenders should prioritize verifying affected systems, especially those using decompress-zip version 0.3.3 or earlier, and assess exposure to potential arbitrary file overwrite, application compromise, or remote code execution.

  • Potential arbitrary file overwrite
  • Possible application compromise
  • Remote code execution risk in certain environments

Technical summary

The vulnerability in Bower decompress-zip through version 0.3.3 improperly validates archive entry paths during ZIP extraction, allowing crafted ZIP archives to write files outside the intended extraction directory. This could lead to arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. The vulnerability is located in lib/decompress-zip.js and involves improper validation of archive entry paths during ZIP extraction. Defenders should prioritize verifying affected systems, especially those using decompress-zip version 0.3.3 or earlier.

Defensive priority

Defenders should prioritize verifying affected systems, especially those using decompress-zip version 0.3.3 or earlier, and assess exposure to potential arbitrary file overwrite.

Recommended defensive actions

  • Verify affected systems, especially those using decompress-zip version 0.3.3 or earlier
  • Assess exposure to potential arbitrary file overwrite
  • Consider upgrading to a patched version of decompress-zip
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and source item provide details on the path traversal vulnerability in Bower decompress-zip. However, additional information on exploitation, impact, and remediation is limited. Defenders should verify affected systems, especially those using decompress-zip version 0.3.3 or earlier, and assess exposure to potential arbitrary file overwrite. The vulnerability is located in lib/decompress-zip.js and involves improper validation of archive entry paths during ZIP extraction.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-107709 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-107709

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-107709 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107709

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Bower decompress-zip has a path traversal vulnerability

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107709.json

    cve_program_cvelist_v5

  • Source reference

    Unverified legacy reference

    URL: https://github.com/bower/decompress-zip

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://moizxsec.github.io/writeups/decompress-zip-zip-slip-sibling-prefix-bypass/

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.