Review
Bower Decompress-Zip
CVE published 2026-10-08
CVE-2026-107709
A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability improperly validates archive entry paths during ZIP extraction, allowing crafted ZIP archives to write files outside the intended extraction directory. This could lead to arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling pa [truncated]