Executive brief
pnpm is a package manager used to install and manage dependencies for Node.js projects. A path traversal vulnerability in its bin linking mechanism allows malicious npm packages to create or overwrite files outside the intended node_modules/.bin directory, potentially enabling attackers to modify configuration files, scripts, or other sensitive files on a developer's system or in CI/CD pipelines.
Technical details
The vulnerability is a path traversal (CWE-22) in pnpm's bin name validation and normalization logic. Bin names starting with "@" bypass the validation filter, and the normalizeBinName function incompletely strips the scope prefix, preserving path traversal sequences like "../../" in the resulting name. When the normalized name is used directly in path.join() without further validation, an attacker can craft a malicious npm package with a bin entry like "@scope/../../.npmrc" that, after normalization, becomes "../../.npmrc", allowing file creation outside node_modules/.bin. The attack requires a user to install the malicious package, but no authentication or special privileges are required. The vulnerability affects all pnpm versions up to 10.28.0; version 10.28.1 and later contain fixes.
Affected products
- pnpm pnpm <= 10.28.0
Timeline
- 2026-01-26: disclosed
- 2026-01-26: patched: pnpm version 10.28.1 released with fix