GHSA-xpqm-wm3m-f34h
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
Quick fix
GHSA-xpqm-wm3m-f34h — pnpm: upgrade to the fixed version with the command below.
npm install pnpm@10.28.1Details
### Summary A path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validation, and after scope normalization, path traversal sequences like `../../` remain intact.
### Details The vulnerability exists in the bin name validation and normalization logic:
**1. Validation Bypass (`pkg-manager/package-bins/src/index.ts`)**
The filter allows any bin name starting with `@` to pass through without validation:
```typescript .filter((commandName) => encodeURIComponent(commandName) === commandName || commandName === '' || commandName[0] === '@' // <-- Bypasses validation ) ```
**2. Incomplete Normalization (`pkg-manager/package-bins/src/index.ts`)**
```typescript function normalizeBinName (name: string): string { return name[0] === '@' ? name.slice(name.indexOf('/') + 1) : name } // Input: @scope/../../evil // Output: ../../evil <-- Path traversal preserved! ```
**3. Exploitation (`pkg-manager/link-bins/src/index.ts:288`)**
The normalized name is used directly in `path.join()` without validation.
### PoC 1. Create a malicious package: ```json { "name": "malicious-pkg", "version": "1.0.0", "bin": { "@scope/../../.npmrc": "./malicious.js" } } ```
2. Install the package: ```bash pnpm add /path/to/malicious-pkg ```
3. Observe `.npmrc` created in project root (outside node_modules/.bin).
### Impact - All pnpm users who install npm packages - CI/CD pipelines using pnpm - Can overwrite config files, scripts, or other sensitive files
Verified on pnpm main @ commit 5a0ed1d45.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/pnpm/pnpm/security/advisories/GHSA-xpqm-wm3m-f34h[WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-23890[ADVISORY]
- https://github.com/pnpm/pnpm/commit/8afbb1598445d37985d91fda18abb4795ae5062d[WEB]
- https://github.com/pnpm/pnpm[PACKAGE]
- https://github.com/pnpm/pnpm/releases/tag/v10.28.1[WEB]