Summary pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependency nodes. As a re…
| CVE ID | CVE-2026-50016 |
| Vendor | npm |
| Affected Product | pnpm |
| Vulnerability Type | Vulnerability |
| CVSS Score | 8.8 (HIGH) |
| Actively Exploited | ❌ No known exploitation |
| Patch Status | See Vendor Advisory → |
| Reported By | CYBERDUDEBIVASH SENTINEL APEX Intelligence (via github_advisories) |
#
pnpm install - ignore-scripts to replace paths in the current project with symlinks to attacker-controlled dependency package directories. .git/hooks is only one useful target. The same primitive can replace other project-local paths that are consumed by later tools, for example: - .husky or .githooks for Git hook dispatchersscripts/, tools/, bin/, or tests/ for project scripts and CI commands.github/actions/ for local GitHub Actions used later in the workflowdist/ or other publish/build output directories bSigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.