Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-82392

Опубликовано: 31 авг. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user's privileges. This issue is fixed in versions 10.34.5 and 11.11.0.

A flaw was found in pnpm, a package manager. An attacker can craft a malicious pnpm-lock.yaml file that, when processed by a user running pnpm install, allows package contents to be written outside the intended node_modules directory. If the system is configured to allow lifecycle scripts, this path traversal vulnerability can lead to arbitrary code execution with the user's privileges.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7amq-broker-bin.zipNot affected
Red Hat AMQ Broker 7amq-broker-maven-repository.zipNot affected
Red Hat Build of Keycloakkeycloak-operator.redhat-00001.zipNot affected
Red Hat Build of Keycloakrhbk-quarkus-dist.zipNot affected
Red Hat Hardened ImagesjaegerNot affected
Red Hat Hardened Imagesprometheus3.13Not affected
Red Hat JBoss Enterprise Application Platform 8jboss-eap.1-runtime-maven-repository.zipNot affected
Red Hat JBoss Enterprise Application Platform 8jboss-eap-runtime-maven-repository.zipNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packjboss-eap.1-runtime-maven-repository.zipNot affected
Red Hat JBoss Enterprise Application Platform Expansion Packjboss-eap-runtime-maven-repository.zipNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2526555pnpm: pnpm: Arbitrary Code Execution via Path Traversal

EPSS

Процентиль: 33%
0.00397
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
16 дней назад

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user's privileges. This issue is fixed in versions 10.34.5 and 11.11.0.

CVSS3: 7.1
debian
16 дней назад

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.1 ...

CVSS3: 7.1
github
14 дней назад

pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph

EPSS

Процентиль: 33%
0.00397
Низкий

7.1 High

CVSS3