Junglewise Threat Intelligence

CVE-2026-101044: pnpm path traversal in lockfile alias validation

CVE-2026-101044 · Severity: high · CVSS 7.1 · Published 2026-09-27

Vendors: Pnpm.

Executive brief

pnpm is a package manager for JavaScript that installs project dependencies. Versions 12.0.0-alpha.0 through 12.0.0-alpha.4 fail to validate dependency alias paths from lockfiles, allowing attackers to create symlinks and directories outside the intended project directory when a user installs with a malicious lockfile. This could expose the system to arbitrary file manipulation and potential code execution through specially crafted links.

Technical details

The pacquet Rust component in pnpm does not sanitize dependency alias paths from lockfiles before using them in filesystem operations, allowing path traversal sequences like '../../' to escape the node_modules boundary. An attacker-controlled lockfile combined with --trust-lockfile or frozen lockfile mode permits creation of symlinks and directories outside the intended containment. The fix validates all dependency names and virtual-store paths using a safe-join helper before any filesystem materialization, rejecting traversal and absolute paths with ERR_PNPM_INVALID_DEPENDENCY_NAME.

Affected products

  • pnpm pnpm >=12.0.0-alpha.0, <12.0.0-alpha.5

Timeline

  • 2026-09-27: disclosed
  • 2026-09-27: patched: Fixed in version 12.0.0-alpha.5

References

Related threats