CVE-2026-23888General(pnpm / pnpm)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious ZIP entries containing `../` or absolute paths that escape the extraction root via AdmZip's `extractAllTo`, and (2) The `BinaryResolution.prefix` field is concatenated into the extraction path without validation, allowing a crafted prefix like `../../evil` to redirect extracted files outside `targetDir`. The issue impacts all pnpm users who install packages with binary assets, users who configure custom Node.js binary locations and CI/CD pipelines that auto-install binary dependencies. It can lead to overwriting config files, scripts, or other sensitive files leading to RCE. Version 10.28.1 contains a patch.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22CWE-23CWE-426

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-02: 1Technical Details · 2026-02-02: 102-02
Signal classification1 categories
General
1100.0%
Full discourse1 post
  • _cr0w_@f3dscr0w
    General

    Supply chain vulnerabilities in open-source like pnpm's path traversal (CVE-2026-23888) allow malicious packages to wreak havoc. Always verify dependencies. What's your go-to for secure package management? #AppSec #NodeJS

    Post summary

    The tweet references a path traversal vulnerability in pnpm (CVE-2026-23888) and urges users to verify dependencies, but it provides no PoC, exploit, patch, or evidence of active exploitation.

    0000061
    32 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more