PT-2026-52514 · Pnpm · Pnpm
CVSS v3.1
7.3
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pnpm versions prior to 10.34.0
pnpm versions prior to 11.4.0
Description
The patch application pipeline (@pnpm/patch-package) fails to validate file paths extracted from .patch files. An attacker can provide a malicious patch file containing
../../ sequences in the diff --git header paths to traverse outside the package directory. This allows the attacker to write controlled content to or delete arbitrary files on the filesystem with the privileges of the user executing the install command.Recommendations
Update pnpm to version 10.34.0 or later.
Update pnpm to version 11.4.0 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pnpm