PT-2026-55947 · Pnpm · Pnpm
CVSS v3.1
8.2
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
pnpm versions prior to 10.34.4
pnpm versions prior to 11.8.0
Description
pnpm accepts package names from the
configDependencies section of the env lockfile and uses them directly when creating config dependency symlinks under node modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml file where the env-lockfile document contains a traversal-shaped config dependency name. During the installation process, pnpm creates a symlink at a path derived from that name, which can lead to path traversal.Recommendations
Update to version 10.34.4.
Update to version 11.8.0.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pnpm