
Nineteen years separate the first cataloged package manager path traversal (CVE-2007-0469) from this year's rediscovery (CVE-2026-34591, CVE-2026-35206). Same bug class. Same archive-extraction primitive. Different ecosystem. A new survey by Nesbitt catalogs a dozen CWE patterns that hit npm, PyPI, RubyGems, Composer, Cargo, Go, Helm, NuGet, and Conda over and over. A few standouts: Argument injection into VCS tools - six separate CVEs in one tool alone across git, hg, and Perforce wrappers (CVE-2021-29472, CVE-2022-36069, CVE-2021-43809, CVE-2023-5752, CVE-2022-24440, plus one more). Integrity checks that fail open: CVE-2016-1252 (clearsigned parser accepted unsigned content), CVE-2022-31156 (sig check silently skipped on error), CVE-2022-46176 (missing SSH host key on git index clones). Dependency confusion was already CVE-2013-0334 - eight years before its 2021 fame. Terminal escape sequences in package metadata: at least nine CVEs across four ecosystems. CocoaPods CVE-2024-38368: an orphaned admin API was left in place for ten years, until a researcher used it to claim 1,800 packages. The thesis: knowledge doesn't transfer between projects. Every ecosystem rediscovers the same dozen bugs from scratch. http://nesbitt.io/2026/05/04/package-manager-cwes.html
Post summary
The text surveys recurring package‑manager vulnerabilities across ecosystems, provides technical details of the attack classes, but offers no PoC, exploit code, patch info, or evidence of active exploitation.
