Bug 2542140 (CVE-2026-101044)

Summary: CVE-2026-101044 pnpm: pnpm: Arbitrary file creation outside project directory via lockfile path traversal
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, bstansbe, csuconic, dbruscin, dlofthou, drichtar, ehugonne, gbenhaim, gtully, istudens, ivassile, iweiss, jsherman, kvanderr, mosmerov, mposolda, msvehla, niyer, nwallace, pberan, pesilva, pjindal, pmackay, rgemmell, rgodfrey, rmartinc, rstancel, ssilvert, sthorger, tbish, thjenkin, tlavocat, twaugh, vdosoudi, vmuzikar
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in pnpm. The package manager does not properly sanitize dependency names and alias paths specified within project lockfiles. By convincing a user or build system to install a project containing a crafted lockfile, an attacker can exploit this path traversal issue to create directories and symbolic links outside the intended project directory. This flaw can lead to unauthorized file manipulation and compromise the integrity of the host system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-09-27 17:21:45 UTC
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and node_modules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERR_PNPM_INVALID_DEPENDENCY_NAME.