UNIX symbolic link following in pnpm - #VU153387
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to access files outside a git dependency repository.
The vulnerability exists due to improper symbolic link resolution in git dependency subpath handling when processing a dependency with a #path: subpath. A remote attacker can supply a git dependency containing a symlink in that subpath to access files outside a git dependency repository.