Bug 2542140 (CVE-2026-101044)
| Summary: | CVE-2026-101044 pnpm: pnpm: Arbitrary file creation outside project directory via lockfile path traversal | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, bstansbe, csuconic, dbruscin, dlofthou, drichtar, ehugonne, gbenhaim, gtully, istudens, ivassile, iweiss, jsherman, kvanderr, mosmerov, mposolda, msvehla, niyer, nwallace, pberan, pesilva, pjindal, pmackay, rgemmell, rgodfrey, rmartinc, rstancel, ssilvert, sthorger, tbish, thjenkin, tlavocat, twaugh, vdosoudi, vmuzikar |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in pnpm. The package manager does not properly sanitize dependency names and alias paths specified within project lockfiles. By convincing a user or build system to install a project containing a crafted lockfile, an attacker can exploit this path traversal issue to create directories and symbolic links outside the intended project directory. This flaw can lead to unauthorized file manipulation and compromise the integrity of the host system.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
|
Description
OSIDB Bzimport
2026-09-27 17:21:45 UTC
|