Improper Resolution of Path Equivalence in pnpm - #VU153379
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to make distinct dependencies share a virtual store directory.
The vulnerability exists due to improper resolution of path equivalence in virtual store directory naming when deriving directory names for URL or local path dependencies. A local user can supply dependency references that differ by +, #, :, or ? in one reference and / in another to make distinct dependencies share a virtual store directory.
Git dependencies pinned with # are also subject to these directory-name collisions.