CVE-2026-50016Disclosure(pnpm / pnpm)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pnpm pnpm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a result, a registry package can cause `pnpm install --ignore-scripts` to replace paths in the current project with symlinks to attacker-controlled dependency package directories. This vulnerability is fixed in 10.34.0 and 11.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 5 classified signals
  • Peaked 2d ago at 3 mentions (2026-06-25); latest day: 1
  • 5 total mentions across 3 days

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline5 mentions / 3d
01223Mentions · 2026-06-25: 3Mentions · 2026-06-26: 1Mentions · 2026-06-27: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 1Technical Details · 2026-06-27: 106-2506-2606-27
Signal classification1 categories
Disclosure
5100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-06-253
Disclosure3
2026-06-261
Disclosure1
2026-06-271
Disclosure1
Full discourse5 posts
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - pnpm transitive dependency alias path traversal enables symlink hijack (CVE-2026-50016) pnpm is vulnerable when processing transitive dependency aliases from registry package metadata, allowing an attacker to inject path traversal segments that are later used during dependency linking. The root cause is path traversal / improper input validation where untrusted alias strings are treated as filesystem paths. An attacker exploits this by publishing or compromising a registry package with a crafted alias so that a victim running pnpm install (including pnpm install --ignore-scripts) links dependencies into attacker-chosen locations via symlinks, no script execution required. Impact includes arbitrary project file replacement via symlinked paths, dependency hijacking, and potential follow-on code execution when the project is built or run, plus broader supply-chain compromise. 👉 Affected: pnpm < 10.34.0 and 11.0.0–11.3.x | Upgrade to 10.34.0 or 11.4.0

    Post summary

    The post discloses a path‑traversal flaw in pnpm’s transitive dependency alias handling that enables symlink hijacking, details how the vulnerability can be leveraged, and advises upgrading to patched releases.

    0001172
    231 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 pnpm, Path Traversal via Transitive Dependency Alias, #CVE-2026-50016 (High) -DC-Jun2026-710 https://dailycve.com/pnpm-path-traversal-via-transitive-dependency-alias-cve-2026-50016-high-dc-jun2026-710/

    Post summary

    A newly reported CVE‑2026‑50016, a high severity path traversal vulnerability in pnpm via transitive dependency alias, has been disclosed.

    0001055
    216 followersView on X
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 25, 2026 🔴 CRITICAL: CVE-2026-50016 (pnpm/pnpm) AAS 13.2 🔴 CRITICAL: CVE-2026-55698 (pnpm/pnpm) AAS 13.2 20 vulnerabilities — CRITICAL: 2, HIGH: 18 Full bulletin: https://aretiq.ai/bulletins/2026-06-25/

    Post summary

    The bulletin lists two critical CVEs for pnpm/pnpm but provides no additional details, PoC, or exploitation status. It serves as a simple disclosure announcement.

    00010105
    191 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50016 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. D… https://www.cve.org/CVERecord?id=CVE-2026-50016 ----- Traducción: CVE-2026-50016 pnp… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-50016, a path traversal flaw in pnpm's transitive dependency alias handling, noting affected versions and linking to the official CVE record, but provides no PoC, exploit, or evidence of active exploitation.

    0000037
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50016 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. D… https://www.cve.org/CVERecord?id=CVE-2026-50016

    Post summary

    The post discloses CVE‑2026‑50016 for pnpm, highlighting a path traversal flaw in transitive dependency alias metadata, but gives no information on PoC, exploitation, or mitigation.

    00000690
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more