{"id":"GHSA-vq4v-j7r6-jq4m","summary":"pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install","details":"## Summary\nWhen resolving a package, pnpm uses the resolved **manifest `name`** as a raw path segment for the isolated-linker import target. A tarball dependency whose `package.json` `name` is a scoped path traversal (`@x/../../…/\u003cabs path\u003e`) is therefore extracted **outside `node_modules`**, to an attacker-chosen absolute path, and can **overwrite existing files** there. Attacker controls the destination, filenames, and contents → arbitrary file write → **code execution** (e.g. `~/.zshrc`, `.git/hooks/pre-commit`, another package's code). Occurs during `pnpm install` **even with `--ignore-scripts`** (no lifecycle scripts run), defeating that safety.\n\nSame class as the just-patched **GHSA-hwx4** (transitive-dependency *alias* traversal) and **GHSA-v23m** (`stage download` manifest name/version traversal), in a sink their fixes did not cover: the isolated-linker import target keyed by the resolved **name**.\n\n## Root cause\n- The isolated-linker import target is built with a raw `path.join(modules, \u003cresolved name\u003e)` in `installing/deps-resolver/src/resolvePeers.ts:706`, `installing/deps-resolver/src/index.ts:614`, and `deps/graph-builder/src/lockfileToDepGraph.ts:233` — **without** the `safeJoinModulesDir` guard used on the symlink/hoisted/bin paths (`installing/deps-restorer/src/lockfileToHoistedDepGraph.ts:222`). The store location is `node_modules/.pnpm/\u003cid\u003e/node_modules/\u003cname\u003e`, so a traversal `\u003cname\u003e` escapes.\n- The only resolve-time name gate (`resolving/npm-resolver/src/pickPackage.ts:753`) rejects only *unscoped* names containing `/`, so a **scoped** `@x/../..` passes.\n\n## Steps to reproduce\nSelf-contained PoC (real `pnpm@11.9.0`; loopback tarball server; escape target is a throwaway temp dir):\n```\nnpm i pnpm@11.9.0\n# host a tarball whose package.json name = \"@x/\"+\"../\".repeat(25)+\"\u003cabs\u003e/OUTSIDE\"; victim depends on the http URL\npnpm install --ignore-scripts\n```\nConfirmed output (`repro/poc.mjs`, exit 0):\n```\nescape dir is outside the project        : true\nnew file implanted outside node_modules  : true\npre-existing file OVERWRITTEN            : true\n*** CONFIRMED: a tarball dependency wrote & overwrote files OUTSIDE the project during `pnpm install --ignore-scripts` ***\n```\n\n## Remediation\nRoute the isolated-linker import-target joins (`resolvePeers.ts:706`, `deps-resolver/index.ts:614`, `lockfileToDepGraph.ts:233`) through `safeJoinModulesDir` (as the hoisted linker already does), and/or enforce `validate-npm-package-name` on the resolved manifest name (close the scoped-name gap at `pickPackage.ts:753`) so the import target rejects a traversal name and re-asserts containment before any write.","aliases":["CVE-2026-82393"],"modified":"2026-09-02T14:45:05.975185716Z","published":"2026-09-02T14:36:59Z","database_specific":{"github_reviewed_at":"2026-09-02T14:36:59Z","nvd_published_at":"2026-08-31T22:17:22Z","cwe_ids":["CWE-22","CWE-73","CWE-94"],"severity":"HIGH","github_reviewed":true},"references":[{"type":"WEB","url":"https://github.com/pnpm/pnpm/security/advisories/GHSA-vq4v-j7r6-jq4m"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-82393"},{"type":"WEB","url":"https://github.com/pnpm/pnpm/pull/12872"},{"type":"WEB","url":"https://github.com/pnpm/pnpm/pull/12890"},{"type":"WEB","url":"https://github.com/pnpm/pnpm/commit/51300fd41c5e4c8f47635108e373cc3d1f324fa7"},{"type":"WEB","url":"https://github.com/pnpm/pnpm/commit/78e29fe5583a1e5d69ea05e414eff310f78d5ed9"},{"type":"PACKAGE","url":"https://github.com/pnpm/pnpm"},{"type":"WEB","url":"https://github.com/pnpm/pnpm/releases/tag/v10.34.5"},{"type":"WEB","url":"https://github.com/pnpm/pnpm/releases/tag/v11.11.0"}],"affected":[{"package":{"name":"pnpm","ecosystem":"npm","purl":"pkg:npm/pnpm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"10.34.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vq4v-j7r6-jq4m/GHSA-vq4v-j7r6-jq4m.json"}},{"package":{"name":"pnpm","ecosystem":"npm","purl":"pkg:npm/pnpm"},"ranges":[{"type":"SEMVER","events":[{"introduced":"11.0.0"},{"fixed":"11.11.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/09/GHSA-vq4v-j7r6-jq4m/GHSA-vq4v-j7r6-jq4m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}