UNIX symbolic link following in pnpm - #VU153390
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to include files from outside a package directory during deployment or local installation.
The vulnerability exists due to improper symbolic link resolution in package deployment and local package installation when following package symlinks. A local user can provide a package symlink pointing outside the package directory to include files from outside a package directory during deployment or local installation.
Exploitation requires the deployAllFiles setting to be enabled.