CVE-2026-107709 | bower decompress-zip up to 0.3.3 lib/decompress-zip.js path traversal
A vulnerability identified as critical has been detected in bower decompress-zip up to 0.3.3. The affected element is an unknown function of the file lib/decompress-zip.js. The manipulation leads to path traversal.
This vulnerability is uniquely identified as CVE-2026-107709. The attack is possible to be carried out remotely. No exploit exists.VulDB Recent EntriesRead More