THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vq4v-j7r6-jq4m (high) — pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install

[GHSA] GHSA-vq4v-j7r6-jq4m (high) — pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install

medgithub_advisoriesPublished 2026-09-02

GHSA-vq4v-j7r6-jq4m Severity: high CVE: CVE-2026-82393

pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install

## Summary When resolving a package, pnpm uses the resolved **manifest `name`** as a raw path segment for the isolated-linker import target. A tarball dependency whose `package.json` `name` is a scoped path traversal (`@x/../../…/<ab

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vq4v-j7r6-jq4m