pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config (CVE-2026-59195)
Description
pnpm versions prior to 10.34.4 and 11.8.0 contain a path traversal vulnerability in the configDependencies env lockfile feature. A malicious pnpm-lock.yaml file can specify a crafted config dependency name that causes pnpm to create symlinks outside the intended node_modules/.pnpm-config directory during installation. This can lead to unauthorized symlink creation and potential integrity issues. The vulnerability is fixed in versions 10.34.4 and 11.8.0.
CVSS v3.1
Score 8.2high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
pnpm is a package manager that, before versions 10.34.4 and 11.8.0, accepts package names from the env lockfile's configDependencies section and uses these names directly to create symlinks under node_modules/.pnpm-config. A malicious repository can include a specially crafted pnpm-lock.yaml file with a traversal-shaped config dependency name, causing pnpm install to create symlinks outside the intended directory. This path traversal vulnerability allows symlink creation outside the node_modules/.pnpm-config directory, potentially leading to unauthorized file system modifications. The issue is resolved in pnpm versions 10.34.4 and 11.8.0.
Potential Impact
This vulnerability allows an attacker who can supply a malicious pnpm-lock.yaml file to cause pnpm to create symbolic links outside the intended directory, potentially leading to unauthorized file system modifications. The CVSS score of 8.2 indicates high severity with impact on integrity and availability. There is no indication of confidentiality impact. No known exploits in the wild have been reported.
Mitigation Recommendations
A fix is available in pnpm versions 10.34.4 and 11.8.0. Users should upgrade to at least these versions to remediate the vulnerability. No additional mitigations are specified.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- BREW-pnpm-CVE-2026-59195
- Osv Schema Version
- 1.7.3
- Ecosystems
- ["Homebrew"]
- Cvss Version
- 3.1
Threat ID: 6ac2c0ae2cdf04f65652344d
Added to database: 10/04/2026, 21:10:06 UTC
Last enriched: 10/04/2026, 21:16:07 UTC
Last updated: 10/05/2026, 06:48:17 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.