<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Tue, 06 Oct 2026 17:02:19 +0000</lastBuildDate>
    <item>
      <title>BREW-pnpm-CVE-2026-82392 — pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph</title>
      <link>https://cve.radiocsirt.org/vuln/brew-pnpm-cve-2026-82392</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pnpm&lt;/p&gt;
&lt;p&gt;pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user&amp;#39;s privileges. This issue is fixed in versions 10.34.5 and 11.11.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Homebrew: pnpm&lt;/p&gt;
&lt;p&gt;pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user&amp;#39;s privileges. This issue is fixed in versions 10.34.5 and 11.11.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/brew-pnpm-cve-2026-82392</guid>
    </item>
    <item>
      <title>EUVD-2026-362484</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-362484</link>
      <description>EUVD-2026-362484</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-362484</guid>
    </item>
    <item>
      <title>fkie_cve-2026-82392</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-82392</link>
      <description>&lt;p&gt;pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user&amp;#39;s privileges. This issue is fixed in versions 10.34.5 and 11.11.0.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user&amp;#39;s privileges. This issue is fixed in versions 10.34.5 and 11.11.0.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-82392</guid>
    </item>
    <item>
      <title>GHSA-c59q-g84q-2gj5 — pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-c59q-g84q-2gj5</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: pnpm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The virtual store linker constructs package installation directories using `path.join(modules, pkgName)` where `pkgName` is extracted from lockfile `packages` keys via `dp.parse(depPath).name` without validation. A crafted `pnpm-lock.yaml` with traversal sequences in depPath keys (e.g., `../../../tmp/pwned@1.0.0`) causes package content to be written to arbitrary filesystem paths during `pnpm install`.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix of GHSA-fr4h-3cph-29xv — the `safeJoinModulesDir` containment helper was applied to the hoisted linker and `symlinkDependency` but NOT to the virtual store linker&amp;#39;s `lockfileToDepGraph.ts:233`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;`dp.parse()` at `pnpm11/deps/path/src/index.ts:135` extracts the package name as:
```typescript
const name = dependencyPath.substring(0, sepIndex)
```&lt;/p&gt;
&lt;p&gt;This is a raw substring operation with zero validation that `name` is a valid npm package name. A depPath of `../../../tmp/pwned@1.0.0` yields `name = &amp;#39;../../../tmp/pwned&amp;#39;`.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code Path&lt;/p&gt;
&lt;p&gt;1. `pnpm-lock.yaml` → `lockfile.packages[&amp;#39;../../../../../../../tmp/pwned@1.0.0&amp;#39;]` (attacker-controlled lockfile key)
2. `nameVerFromPkgSnapshot(depPath, pkgSnapshot)` at `lockfile/utils/src/nameVerFromPkgSnapshot.ts:16` → calls `dp.parse(depPath)` → returns `{ name: &amp;#39;../../../../../../../tmp/pwned&amp;#39; }`
3. `lockfileToDepGraph.ts:232` → `modules = path.join(dirInVirtualStore, &amp;#39;node_modules&amp;#39;)`
4. `lockfileToDepGraph.ts:233` → `dir = path.join(modules, pkgName)` → resolves to `/…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: pnpm&lt;/p&gt;
&lt;p&gt;## Summary&lt;/p&gt;
&lt;p&gt;The virtual store linker constructs package installation directories using `path.join(modules, pkgName)` where `pkgName` is extracted from lockfile `packages` keys via `dp.parse(depPath).name` without validation. A crafted `pnpm-lock.yaml` with traversal sequences in depPath keys (e.g., `../../../tmp/pwned@1.0.0`) causes package content to be written to arbitrary filesystem paths during `pnpm install`.&lt;/p&gt;
&lt;p&gt;This is an incomplete fix of GHSA-fr4h-3cph-29xv — the `safeJoinModulesDir` containment helper was applied to the hoisted linker and `symlinkDependency` but NOT to the virtual store linker&amp;#39;s `lockfileToDepGraph.ts:233`.&lt;/p&gt;
&lt;p&gt;## Details&lt;/p&gt;
&lt;p&gt;### Root Cause&lt;/p&gt;
&lt;p&gt;`dp.parse()` at `pnpm11/deps/path/src/index.ts:135` extracts the package name as:
```typescript
const name = dependencyPath.substring(0, sepIndex)
```&lt;/p&gt;
&lt;p&gt;This is a raw substring operation with zero validation that `name` is a valid npm package name. A depPath of `../../../tmp/pwned@1.0.0` yields `name = &amp;#39;../../../tmp/pwned&amp;#39;`.&lt;/p&gt;
&lt;p&gt;### Vulnerable Code Path&lt;/p&gt;
&lt;p&gt;1. `pnpm-lock.yaml` → `lockfile.packages[&amp;#39;../../../../../../../tmp/pwned@1.0.0&amp;#39;]` (attacker-controlled lockfile key)
2. `nameVerFromPkgSnapshot(depPath, pkgSnapshot)` at `lockfile/utils/src/nameVerFromPkgSnapshot.ts:16` → calls `dp.parse(depPath)` → returns `{ name: &amp;#39;../../../../../../../tmp/pwned&amp;#39; }`
3. `lockfileToDepGraph.ts:232` → `modules = path.join(dirInVirtualStore, &amp;#39;node_modules&amp;#39;)`
4. `lockfileToDepGraph.ts:233` → `dir = path.join(modules, pkgName)` → resolves to `/…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-c59q-g84q-2gj5</guid>
    </item>
  </channel>
</rss>
