cvedb.io
CVE-2026-50016
HIGH · CVSS 8.8
EPSS exploitation probability: 0%
Published 2026-06-25T18:16:39.303 · Last modified 2026-06-29T23:57:03.630

Summary

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a registry package can cause `pnpm install --ignore-scripts` to replace paths in the current project with symlinks to attacker-controlled dependency package directories. This vulnerability is fixed in 10.34.0 and 11.4.0.

Affected products

pnpm — pnpm

Does this affect you?

Add your gear to cvedb and we'll alert you only when pnpm ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.