<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-07T23:54:42.512592+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-pnpm-cve-2026-59195</id>
    <title>BREW-pnpm-CVE-2026-59195 — pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config</title>
    <updated>2026-10-07T23:54:42.615899+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: pnpm</p>
<p>pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from that name. This vulnerability is fixed in 10.34.4 and 11.8.0.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-pnpm-cve-2026-59195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-333667</id>
    <title>EUVD-2026-333667</title>
    <updated>2026-10-07T23:54:42.615963+00:00</updated>
    <content>EUVD-2026-333667</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-333667"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-59195</id>
    <title>fkie_cve-2026-59195</title>
    <updated>2026-10-07T23:54:42.615980+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious repository can commit a crafted pnpm-lock.yaml whose env-lockfile document contains a traversal-shaped config dependency name. During pnpm install, pnpm installs the config dependency and creates a symlink at a path derived from that name. This vulnerability is fixed in 10.34.4 and 11.8.0.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-59195"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-qrv3-253h-g69c</id>
    <title>GHSA-qrv3-253h-g69c — pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config</title>
    <updated>2026-10-07T23:54:42.616005+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: pnpm</p>
<p>## Summary</p>
<p>`pnpm` accepts package names from the env lockfile `configDependencies` section and uses those names directly when creating config dependency symlinks under `node_modules/.pnpm-config`.</p>
<p>A malicious repository can commit a crafted `pnpm-lock.yaml` whose env-lockfile document contains a traversal-shaped config dependency name such as `../../PWNED_CFGDEP`. During `pnpm install`, pnpm installs the config dependency and creates a symlink at a path derived from that name.</p>
<p>In local testing against pnpm `v11.5.1`, this caused pnpm to create a symlink outside the intended config dependency directory:</p>
<p>```text
expected root: /tmp/pnpm-cfgdep-poc-sznwgunx/victim/node_modules/.pnpm-config
actual path:   /tmp/pnpm-cfgdep-poc-sznwgunx/victim/PWNED_CFGDEP
```</p>
<p>This works with `--ignore-scripts`, so it does not rely on lifecycle script execution.</p>
<p>## Vulnerable behavior</p>
<p>The vulnerable behavior appears to be that `configDependencies` keys from the env lockfile are trusted as package names and used in filesystem paths without rejecting traversal components.</p>
<p>The relevant pattern is:</p>
<p>```ts
const configModulesDir = path.join(opts.rootDir, 'node_modules/.pnpm-config')</p>
<p>for (const [pkgName, pkg] of Object.entries(normalizedDeps)) {
  const configDepPath = path.join(configModulesDir, pkgName)</p>
<p>const pkgDirInGlobalVirtualStore = path.join(
    globalVirtualStoreDir,
    relPath,
    'node_modules',
    pkgName
  )</p>
<p>await symlinkDir(pkgDirInGlobalVirtualStore, configDepPath)
}
``…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-qrv3-253h-g69c"/>
  </entry>
</feed>
