Path traversal in pnpm - CVE-2026-23888
Published: April 27, 2026
pnpm
Detailed vulnerability description
The vulnerability allows a remote attacker to write arbitrary files outside the intended extraction directory.
The vulnerability exists due to path traversal in pnpm binary fetcher when extracting binary ZIP archives or processing a crafted BinaryResolution.prefix value. A remote attacker can supply a specially crafted ZIP archive or prefix value to write arbitrary files outside the intended extraction directory.
User interaction is required to install a malicious package or otherwise process the crafted binary archive.