Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59195

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from that name. This vulnerability is fixed in 10.34.4 and 11.8.0.

A flaw was found in pnpm, a package manager. A remote attacker could exploit a path traversal vulnerability by crafting a malicious pnpm-lock.yaml file. When a user installs dependencies from such a repository, pnpm incorrectly processes package names from the configDependencies section, leading to the creation of symbolic links outside the intended directory. This allows an attacker to achieve arbitrary file writes within the victim's project directory, potentially extending to other areas of the filesystem.

Отчет

This is an Important path traversal vulnerability in pnpm, a package manager used by Red Hat products such as Red Hat Build of Keycloak, Enterprise Application Platform, Red Hat AMQ, and Konflux. A malicious repository containing a specially crafted pnpm-lock.yaml file can lead to the creation of arbitrary symlinks outside the intended node_modules/.pnpm-config directory during pnpm install. This provides an attacker with a filesystem write primitive, even when --ignore-scripts is used, increasing the risk of unauthorized file manipulation.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
https://bugzilla.redhat.com/show_bug.cgi?id=2497370pnpm: pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

EPSS

Процентиль: 17%
0.00257
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
nvd
28 дней назад

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from that name. This vulnerability is fixed in 10.34.4 and 11.8.0.

CVSS3: 8.2
debian
28 дней назад

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts p ...

EPSS

Процентиль: 17%
0.00257
Низкий

8.2 High

CVSS3

Уязвимость CVE-2026-59195