


Perceptive Security
SOC/SIEM Consultancy

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys wi…
Published:
31 augustus 2026 om 00:00:00
Alert date:
1 september 2026 om 00:05:29
Source:
nvd.nist.gov
Supply Chain & Dependencies, Web Technologies
A path traversal vulnerability exists in pnpm package manager versions prior to 10.34.5 and from 11.0.0 until 11.11.0. The flaw stems from pnpm parsing package names from attacker-controlled pnpm-lock.yaml files without proper validation. The unvalidated package name is passed to path.join(), storeController.importPackage, and related functions, enabling package contents to be written outside the intended node_modules directory. If lifecycle scripts are permitted via dangerouslyAllowAllBuilds or a matching allowBuilds configuration, an attacker can achieve arbitrary code execution with the victim user's privileges. The attack vector requires a user to run pnpm install against a malicious or compromised lockfile. This represents a supply chain risk, particularly in CI/CD environments or shared repositories. Fixes are available in pnpm versions 10.34.5 and 11.11.0.
Technical details
Mitigation steps:
Affected products:
pnpm < 10.34.5
pnpm 11.0.0 - 11.10.x
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82392
https://github.com/pnpm/pnpm/commit/51300fd41c5e4c8f47635108e373cc3d1f324fa7
https://github.com/pnpm/pnpm/commit/78e29fe5583a1e5d69ea05e414eff310f78d5ed9
https://github.com/pnpm/pnpm/pull/12872
https://github.com/pnpm/pnpm/pull/12890
https://github.com/pnpm/pnpm/releases/tag/v10.34.5
https://github.com/pnpm/pnpm/releases/tag/v11.11.0
https://github.com/pnpm/pnpm/security/advisories/GHSA-c59q-g84q-2gj5
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
