Executive brief
Bower is a widely-used JavaScript package manager. Versions before 1.8.8 fail to validate symbolic links when extracting archives, allowing an attacker to craft a malicious package that overwrites arbitrary files on a developer's system during installation. This could lead to code execution, data loss, or compromised development environments.
Technical details
This is a path traversal vulnerability (CWE-22) in Bower's archive extraction logic. When Bower extracts tar.gz packages, it does not validate that symbolic links resolve to targets outside the extraction root directory. An attacker can craft a malicious package with a symlink pointing to an arbitrary path (e.g., /etc/passwd or a file in the application directory), and when extracted, this symlink will overwrite the target file. No authentication or user interaction beyond running `bower install` is required; the attack is triggered automatically during package installation. The vulnerability was patched in version 1.8.8 by adding proper symlink target validation.
Affected products
- Bower bower prior to 1.8.8
Timeline
- 2019-09-13: disclosed: NVD publication date
- 2019-09-17: patched: Patch released in bower 1.8.8
- 2019-09-17: advisory