CVE-2026-82392: Pnpm
High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.
pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfileToDepGraph.ts and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts. The name reaches path.join(modules, pkgName), storeController.importPackage, and pnpm11/lockfile/to-pnp/src/index.ts, allowing package contents to be written outside node_modules when a user runs pnpm install. When dangerouslyAllowAllBuilds or a matching allowBuilds entry permits lifecycle scripts, the escaped package can execute code with the user's privileges. This issue is fixed in versions 10.34.5 and 11.11.0.
Affected products
- Pnpm Pnpm: before 10.34.5 (fixed in 10.34.5); from 11.0.0, before 11.11.0 (fixed in 11.11.0)
Published 2026-08-31. Last modified 2026-09-09.