CVE-2026-107709

Source
https://cve.org/CVERecord?id=CVE-2026-107709
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107709.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-107709
Published
2026-10-08T16:59:10Z
Modified
2026-10-10T02:47:28Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Bower decompress-zip has a path traversal vulnerability
Details

A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in lib/decompress-zip.js improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths.

Database specific
{
    "cna_assigner": "certcc",
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/107xxx/CVE-2026-107709.json"
}
References

Affected packages

Git / github.com/bower/decompress-zip

Affected ranges

Type
GIT
Repo
https://github.com/bower/decompress-zip
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "0.3.3"
        },
        {
            "fixed": "0.3.3"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

0.*
0.2.0
0.2.1
0.3.0
v0.*
v0.0.1
v0.0.2
v0.0.4
v0.0.5
v0.0.6
v0.0.7
v0.0.8
v0.1.0
v0.3.1
v0.3.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-107709.json"