Junglewise Threat Intelligence

CVE-2026-23890: pnpm scoped bin name path traversal

CVE-2026-23890 · Severity: low · CVSS 3.1 · Published 2026-01-26

Technologies: pnpm (npm). Vendors: npm, Pnpm.

Executive brief

pnpm is a package manager used to install and manage dependencies for Node.js projects. A path traversal vulnerability in its bin linking mechanism allows malicious npm packages to create or overwrite files outside the intended node_modules/.bin directory, potentially enabling attackers to modify configuration files, scripts, or other sensitive files on a developer's system or in CI/CD pipelines.

Technical details

The vulnerability is a path traversal (CWE-22) in pnpm's bin name validation and normalization logic. Bin names starting with "@" bypass the validation filter, and the normalizeBinName function incompletely strips the scope prefix, preserving path traversal sequences like "../../" in the resulting name. When the normalized name is used directly in path.join() without further validation, an attacker can craft a malicious npm package with a bin entry like "@scope/../../.npmrc" that, after normalization, becomes "../../.npmrc", allowing file creation outside node_modules/.bin. The attack requires a user to install the malicious package, but no authentication or special privileges are required. The vulnerability affects all pnpm versions up to 10.28.0; version 10.28.1 and later contain fixes.

Affected products

  • pnpm pnpm <= 10.28.0

Timeline

  • 2026-01-26: disclosed
  • 2026-01-26: patched: pnpm version 10.28.1 released with fix

References

Related threats