PoC Index82,564 CVEs with PoCs

CVE-2026-82392

pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph

HIGH 7.1EPSS 0.4%

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user's privileges. This issue is fixed in versions 10.34.5 and 11.11.0.

Affected
pnpm
CVSS v3.1 GITHUB
7.1 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
EPSS
0.40% chance of exploitation in the next 30 days, 33rd percentile
Published
2026-08-31
Updated
2026-09-01

Proof-of-concept exploits (1)

References