PT-2026-55947 · Pnpm · Pnpm

·

CVE-2026-59195

·

Published

2026-06-27

·

Updated

2026-07-07

CVSS v3.1

8.2

High

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions pnpm versions prior to 10.34.4 pnpm versions prior to 11.8.0
Description pnpm accepts package names from the configDependencies section of the env lockfile and uses them directly when creating config dependency symlinks under node modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml file where the env-lockfile document contains a traversal-shaped config dependency name. During the installation process, pnpm creates a symlink at a path derived from that name, which can lead to path traversal.
Recommendations Update to version 10.34.4. Update to version 11.8.0.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-59195
GHSA-QRV3-253H-G69C

Affected Products

Pnpm