Path traversal in pnpm - #VU153373
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to write files outside the global virtual store.
The vulnerability exists due to path traversal in dependency version handling in pnpm install when processing dependency versions. A remote attacker can supply a dependency version containing path traversal sequences that a victim installs to write files outside the global virtual store.