VYPR
High severity8.8NVD Advisory· Published Jun 25, 2026· Updated Jun 29, 2026

CVE-2026-50016

CVE-2026-50016

Description

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a registry package can cause pnpm install --ignore-scripts to replace paths in the current project with symlinks to attacker-controlled dependency package directories. This vulnerability is fixed in 10.34.0 and 11.4.0.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
pnpmnpm
< 10.34.010.34.0
pnpmnpm
>= 11.0.0, < 11.4.011.4.0

Affected products

3

Patches

Vulnerability mechanics

References

3

News mentions

1