Path traversal in pnpm - #VU153389
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to include files from outside a package directory through bundled dependencies.
The vulnerability exists due to improper restriction of file paths in bundled dependency file collection when packing, publishing, or installing git and local directory dependencies. A remote attacker can supply a package with a bundleDependencies entry pointing outside its directory to include files from outside a package directory through bundled dependencies.