PT-2026-99562 · Npm · Pnpm

CVE-2026-101044

·

Published

2026-09-27

·

Updated

2026-09-27

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions pnpm versions 12.0.0-alpha.0 through 12.0.0-alpha.4
Description The pacquet Rust package-manager component fails to validate dependency alias or name paths from a lockfile before using them in filesystem joins during installation. If a user installs a project using an attacker-supplied lockfile with --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (such as ../../escaped-link) can be used to create symlinks and directories outside the intended project and node modules boundary. This occurs during the creation of dependency and package links, bin destinations, hoisted entries, and virtual-store slots.
Recommendations Update pnpm to version 12.0.0-alpha.5 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101044

Affected Products

Pnpm