Improper Handling of Case Sensitivity in pnpm - #VU153397
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to make distinct dependencies share a virtual store directory.
The vulnerability exists due to ambiguous dependency identifier encoding in virtual store directory naming when mapping URL or local path dependencies to directory names. A remote attacker can supply a dependency identifier with +, #, :, or ? where another identifier has / to make distinct dependencies share a virtual store directory.
Git dependencies pinned with # are also within the scope of this issue.