


Perceptive Security
SOC/SIEM Consultancy

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directl…
Published:
5 juli 2026 om 22:00:00
Alert date:
6 juli 2026 om 19:05:24
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A path traversal vulnerability exists in pnpm, a popular Node.js package manager, affecting versions prior to 10.34.4 and 11.8.0. The flaw resides in how pnpm processes package names from the configDependencies section of the env lockfile without sanitization. A malicious repository can craft a pnpm-lock.yaml file containing traversal-shaped config dependency names, which pnpm then uses directly when creating symlinks under node_modules/.pnpm-config. During a pnpm install operation, this allows an attacker to place symlinks at arbitrary filesystem paths derived from the malicious dependency name. The attack vector is supply chain in nature, requiring a developer to clone and install from a compromised repository. The vulnerability has been patched in pnpm versions 10.34.4 and 11.8.0. Users are strongly advised to upgrade immediately to mitigate the risk.
Technical details
Mitigation steps:
Affected products:
pnpm
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-59195
https://github.com/pnpm/pnpm/security/advisories/GHSA-qrv3-253h-g69c
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
