PT-2026-52515 · Pnpm · Pnpm

·

CVE-2026-50016

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pnpm versions prior to 10.34.0 pnpm versions prior to 11.4.0
Description pnpm allows a transitive dependency alias within registry package metadata to include path traversal segments. During the installation process, pnpm utilizes this alias as a filesystem path when linking dependency nodes. This allows a registry package to cause pnpm install --ignore-scripts to replace project paths with symlinks pointing to dependency package directories controlled by an attacker.
Recommendations Update pnpm to version 10.34.0 or later. Update pnpm to version 11.4.0 or later.

Exploit

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50016
GHSA-HWX4-2J3J-G496

Affected Products

Pnpm