CVE-2026-101044: pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and nodemodules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERRPNPMINVALIDDEPENDENCYNAME.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pacquetto a version that resolves this vulnerability.Fixed in 12.0.0-alpha.5
Event History
Frequently Asked Questions
Who is exposed to this issue?
Projects using the pacquet component shipped in pnpm npm package versions 12.0.0-alpha.0 through before 12.0.0-alpha.5 are exposed when they install an attacker-supplied lockfile with --trust-lockfile or in a frozen-lockfile workflow.
What does an attacker need to exploit it?
An attacker needs to supply or influence a lockfile containing dependency alias or name entries with path-traversal segments. User interaction is required because a user must run the installation using that lockfile.
Are normal installations affected by default?
The described exposure specifically requires installation of an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile. The provided information does not state that ordinary installations without those conditions are affected.
What can be done if upgrading is not immediately possible?
Do not install untrusted lockfiles with --trust-lockfile or frozen-lockfile behavior. Review lockfile dependency aliases and names for traversal segments, absolute paths, platform-specific names, or reserved names before installation.
How can I tell whether remediation is present?
Version 12.0.0-alpha.5 rejects invalid dependency names and virtual-store slot paths before filesystem materialization with ERR_PNPM_INVALID_DEPENDENCY_NAME. Earlier affected versions may create links, directories, bin destinations, hoisted entries, or virtual-store slots outside the project or node_modules boundary when given traversal-containing aliases.