Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Sun, 27 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and node_modules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERR_PNPM_INVALID_DEPENDENCY_NAME. | |
| Title | pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias | |
| First Time appeared |
Pnpm
Pnpm pnpm |
|
| Weaknesses | CWE-22 | |
| CPEs | cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Pnpm
Pnpm pnpm |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-27T17:02:33.798Z
Reserved: 2026-09-27T15:48:49.472Z
Link: CVE-2026-101044
No data.
Status : Received
Published: 2026-09-27T18:16:30.753
Modified: 2026-09-27T18:16:30.753
Link: CVE-2026-101044
No data.
OpenCVE Enrichment
Updated: 2026-09-27T18:30:18Z