Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-50015

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 7.3

Описание

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull request can write attacker-controlled content to or delete arbitrary files on the filesystem during pnpm install, as the user running the install. The diff --git header paths containing ../../ sequences traverse out of the package directory, and the traversal is difficult to catch in code review because patch file diff headers are opaque to most reviewers. This vulnerability is fixed in 10.34.0 and 11.4.0.

A flaw was found in pnpm. An attacker can exploit this by contributing a malicious patch file through a pull request. During the pnpm install process, the patch application pipeline fails to validate file paths extracted from these patch files. This allows the attacker to write or delete arbitrary files on the filesystem, potentially leading to arbitrary code execution or privilege escalation on the system where pnpm install is executed.

Отчет

This is an Important vulnerability in pnpm, a package manager utilized across several Red Hat products. The flaw enables an attacker to perform arbitrary file write or deletion on the filesystem during the pnpm install process by introducing a specially crafted patch file. This is due to insufficient path validation within the patch application pipeline, allowing directory traversal and potentially leading to arbitrary code execution or privilege escalation on the system where the installation is performed.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2493029pnpm: pnpm: Arbitrary file write/delete due to lack of path validation in patch files

7.3 High

CVSS3

Связанные уязвимости

CVSS3: 7.3
nvd
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull request can write attacker-controlled content to or delete arbitrary files on the filesystem during pnpm install, as the user running the install. The diff --git header paths containing ../../ sequences traverse out of the package directory, and the traversal is difficult to catch in code review because patch file diff headers are opaque to most reviewers. This vulnerability is fixed in 10.34.0 and 11.4.0.

CVSS3: 7.3
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch a ...

CVSS3: 7.3
github
около 1 месяца назад

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

7.3 High

CVSS3