Executive brief
pnpm is a package manager for Node.js projects. Versions before 6.15.1 are vulnerable to binary planting attacks on Windows when executing pnpm commands in directories containing malicious content, potentially allowing an attacker to execute arbitrary code.
Technical details
pnpm prior to version 6.15.1 contains an untrusted search path vulnerability (CWE-426) that enables binary planting attacks on Windows systems. The vulnerability occurs when the application uses an unsafe method to locate and execute binaries, allowing an attacker to place malicious executables in a directory where pnpm searches for dependencies. When a user runs pnpm commands in a compromised directory, the malicious binary is executed instead of the legitimate one. The attack requires local access or the ability to place files in directories that will be searched by pnpm. The fix involves replacing the unsafe execa library with safe-execa, which implements proper binary resolution and mitigates path traversal risks. The vulnerability was patched in version 6.15.1.
Affected products
- pnpm pnpm <6.15.1
Timeline
- 2022-03-21: disclosed: NVD publication date
- 2022-03-23: patched: pnpm v6.15.1 released with fix
- 2022-03-23: advisory: GHSA advisory published