Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-101044— pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias

Quick assessment

Affected
pnpm pnpm
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 pnpm npm 包版本 >=12.0.0-alpha.0 且 <12.0.0-alpha.5 中发布的 Rust 包管理器组件 pacquet,未对从锁文件(lockfile)中获取的依赖别名/名称路径在安装时的文件系统路径拼接操作前进行验证。当用户使用 --trust-lockfile 选项或冻结锁文件(frozen lockfile)安装由攻击者提供的锁文件的项目时,包含路径穿越片段(例如 '../../escaped-link')的别名条目会在创建依赖链接、包链接、bin 目标、提升(hoisted)条

CVSS 7.1 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-101044

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias
Source: CVE Program / CVE List V5
Vulnerability Description
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and node_modules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERR_PNPM_INVALID_DEPENDENCY_NAME.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
pnpm pnpm 12.0.0-alpha.0 ~ 12.0.0-alpha.5 -

II. Public POCs for CVE-2026-101044

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-101044

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-101044 (1)

Other References for CVE-2026-101044 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-101044

No comments yet


Leave a comment