THREAT OPS › Threat News › [GHSA] GHSA-vq4v-j7r6-jq4m (high) — pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
[GHSA] GHSA-vq4v-j7r6-jq4m (high) — pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
GHSA-vq4v-j7r6-jq4m Severity: high CVE: CVE-2026-82393
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install
## Summary When resolving a package, pnpm uses the resolved **manifest `name`** as a raw path segment for the isolated-linker import target. A tarball dependency whose `package.json` `name` is a scoped path traversal (`@x/../../…/<ab
Indicators of compromise
- CVE-2026-82393cve
Original source: https://github.com/advisories/GHSA-vq4v-j7r6-jq4m