Junglewise Threat Intelligence

CVE-2023-37478: pnpm tar archive parsing bypass vulnerability

CVE-2023-37478 · Severity: low · CVSS 3.1 · Published 2023-08-01

Vendors: Pnpm.

Executive brief

pnpm is a Node.js package manager used by developers to install JavaScript dependencies. The vulnerability allows an attacker to craft a malicious package that appears legitimate when installed via npm but executes compromised code when installed via pnpm, enabling supply chain attacks on development environments. This occurs because pnpm incorrectly handles tar archives with duplicate files, extracting the first occurrence instead of the final one as per the TAR specification.

Technical details

The vulnerability stems from pnpm's tar-stream extraction logic not conforming to TAR format specification. The TAR format is append-only; when a file appears multiple times, the last occurrence should be extracted. pnpm instead uses the first occurrence, allowing attackers to create tarballs with multiple root directories (e.g., a/, package/, z/) each containing different package.json files. After stripping the first path component (standard practice), the payload depends on extraction order: npm uses the last file (spec-compliant), while pnpm uses the first. This enables supply chain attacks where a package passes registry inspection but executes malicious dependencies when installed via pnpm. The issue affects pnpm versions before 7.33.4 and 8.0.0–8.6.7. Patches are available in v7.33.4 and v8.6.8.

Affected products

  • pnpm pnpm <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/cafs <7.0.5
  • pnpm @pnpm/exe <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/linux-arm64 <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/linux-x64 <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/linuxstatic-arm64 <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/macos-arm64 <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/macos-x64 <7.33.4 or >=8.0.0 <8.6.8
  • pnpm @pnpm/win-x64 <7.33.4 or >=8.0.0 <8.6.8

Timeline

  • 2023-08-01: disclosed: Vulnerability disclosed via GHSA-5r98-f33j-g8h7
  • 2023-07-17: patched: Patches released in v7.33.4 and v8.6.8

References