Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 08 Oct 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 08 Oct 2026 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-22 |
Thu, 08 Oct 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A path traversal vulnerability exists in Bower decompress-zip through version 0.3.3. The vulnerability located in `lib/decompress-zip.js` improperly validates archive entry paths during ZIP extraction. A crafted ZIP archive containing entries that resolve to prefix-sibling directories can cause files to be written outside the intended extraction directory. Successful exploitation may allow arbitrary file overwrite, application compromise, or remote code execution depending on the target environment and writable sibling paths. | |
| Title | Bower decompress-zip has a path traversal vulnerability | |
| References |
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2026-10-08T20:23:46.370Z
Reserved: 2026-10-08T16:57:51.188Z
Link: CVE-2026-107709
Updated: 2026-10-08T20:23:42.560Z
Status : Deferred
Published: 2026-10-08T17:17:16.293
Modified: 2026-10-08T21:17:52.420
Link: CVE-2026-107709
No data.
OpenCVE Enrichment
Updated: 2026-10-08T19:00:07Z