CVE-2026-82393
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifes
CVSS
7.5
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 31 ago 2026 · Última mod.: 1 sept 2026 · CWE-22 · CWE-73 · CWE-94
Sin historial EPSS suficiente todavía.
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-resolver/src/index.ts, and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts, causing package extraction outside node_modules and allowing attacker-controlled files to overwrite arbitrary filesystem paths even when --ignore-scripts is used. The overwrite can replace shell startup files, Git hooks, or installed package code and lead to code execution. This issue is fixed in versions 10.34.5, and 11.11.0.
- github.comhttps://github.com/pnpm/pnpm/commit/51300fd41c5e4c8f47635108e373cc3d1f324fa7
- github.comhttps://github.com/pnpm/pnpm/commit/78e29fe5583a1e5d69ea05e414eff310f78d5ed9
- github.comhttps://github.com/pnpm/pnpm/pull/12872
- github.comhttps://github.com/pnpm/pnpm/pull/12890
- github.comhttps://github.com/pnpm/pnpm/releases/tag/v10.34.5
- github.comhttps://github.com/pnpm/pnpm/releases/tag/v11.11.0
- github.comhttps://github.com/pnpm/pnpm/security/advisories/GHSA-vq4v-j7r6-jq4m
- github.comhttps://github.com/pnpm/pnpm/security/advisories/GHSA-vq4v-j7r6-jq4m