PatchSiren cyber security CVE debrief
CVE-2026-107709 Bower Decompress-Zip CVE debrief
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability improperly validates archive entry paths during ZIP extraction, allowing crafted ZIP archives to write files outside the intended extraction directory. This could lead to arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. Defenders should assess exposure and prioritize verification and potential upgrades.
- Vendor
- Bower Decompress-Zip
- Product
- decompress-zip
- CVSS
- Unknown
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for systems using Bower decompress-zip should assess exposure and prioritize verification and potential upgrades. This includes reviewing system configurations, assessing the risk of arbitrary file overwrite, application compromise, or remote code execution, and considering upgrades to a patched version of decompress-zip.
Why it matters
Defenders should prioritize verifying affected systems, especially those using decompress-zip version 0.3.3 or earlier, and assess exposure to potential arbitrary file overwrite, application compromise, or remote code execution.
- Potential arbitrary file overwrite
- Possible application compromise
- Remote code execution risk in certain environments
Technical summary
The vulnerability in Bower decompress-zip through version 0.3.3 improperly validates archive entry paths during ZIP extraction, allowing crafted ZIP archives to write files outside the intended extraction directory. This could lead to arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. The vulnerability is located in lib/decompress-zip.js and involves improper validation of archive entry paths during ZIP extraction. Defenders should prioritize verifying affected systems, especially those using decompress-zip version 0.3.3 or earlier.
Defensive priority
Defenders should prioritize verifying affected systems, especially those using decompress-zip version 0.3.3 or earlier, and assess exposure to potential arbitrary file overwrite.
Recommended defensive actions
- Verify affected systems, especially those using decompress-zip version 0.3.3 or earlier
- Assess exposure to potential arbitrary file overwrite
- Consider upgrading to a patched version of decompress-zip
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and source item provide details on the path traversal vulnerability in Bower decompress-zip. However, additional information on exploitation, impact, and remediation is limited. Defenders should verify affected systems, especially those using decompress-zip version 0.3.3 or earlier, and assess exposure to potential arbitrary file overwrite. The vulnerability is located in lib/decompress-zip.js and involves improper validation of archive entry paths during ZIP extraction.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-107709 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-107709
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-107709 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-107709
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Bower decompress-zip has a path traversal vulnerability
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/107xxx/CVE-2026-107709.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/bower/decompress-zip
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://moizxsec.github.io/writeups/decompress-zip-zip-slip-sibling-prefix-bypass/
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.