pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped names. During pnpm install, the unvalidated name reaches raw path joins in pnpm11/installing/deps-resolver/src/resolvePeers.ts, pnpm11/installing/deps-resolver/src/index.ts, and pnpm11/deps/graph-builder/src/lockfileToDepGraph.ts, causing package extraction outside node_modules and allowing attacker-controlled files to overwrite arbitrary filesystem paths even when --ignore-scripts is used. The overwrite can replace shell startup files, Git hooks, or installed package code and lead to code execution. This issue is fixed in versions 10.34.5, and 11.11.0.
CVE-2026-82393
This high-severity CVE scores 7.5 under a secondary CVSS source (NVD's own analysis pending). EPSS exploit probability: 0.4%, top 66% of all CVEs by exploit prediction. GitHub Security Advisory data not yet ingested — confidence will rise once GHSA publishes (typical lag: hours to days for open-source ecosystem CVEs; never for infrastructure-only CVEs).
- High severity, but no confirmed exploitation yet
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 7.5
- EG Score
- 7.5(medium)
- EG Risk
- 50(Track*)EG Risk 50/100SSVC: Track*
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity75% × 45%Exploitation40% × 40%Automatability0% × 15%Action: Watch closely — could escalate to Attend. - EPSS PROB
- 0%
- EPSS %ILE
- 34%
- KEV
- Not listed
Published
August 31, 2026
Last Modified
September 1, 2026
Advisory Details (7)
Auto-updated Aug 31, 2026pnpm 11.11
Patch available: pnpm/pnpm v11.11.0
https://github.com/pnpm/pnpm/releases/tag/v11.11.0pnpm 10.34.5
Patch available: pnpm/pnpm v10.34.5
https://github.com/pnpm/pnpm/releases/tag/v10.34.5commit 78e29fe5583a (pnpm/pnpm)
Fix landed in pnpm/pnpm commit 78e29fe5583a — awaiting tagged release
https://github.com/pnpm/pnpm/commit/78e29fe5583a1e5d69ea05e414eff310f78d5ed9commit 51300fd41c5e (pnpm/pnpm)
Fix landed in pnpm/pnpm commit 51300fd41c5e — awaiting tagged release
https://github.com/pnpm/pnpm/commit/51300fd41c5e4c8f47635108e373cc3d1f324fa7fix(security): backport lockfile & manifest name/slot containment to v10
Fix merged in pnpm/pnpm PR #12890 on 2026-07-09 — awaiting tagged release
https://github.com/pnpm/pnpm/pull/12890fix(security): contain lockfile & manifest package names/slots against path traversal (pnpm + pacquet)
Fix merged in pnpm/pnpm PR #12872 on 2026-07-09 — awaiting tagged release
https://github.com/pnpm/pnpm/pull/12872pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install · Advisory · pnpm/pnpm · GitHub
https://github.com/pnpm/pnpm/security/advisories/GHSA-vq4v-j7r6-jq4mWeakness Classification(3)
MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.
Data Freshness Timeline
(refreshed 6× in last 7d / 6× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-09-01 15:41 UTCEG score recompute
- 2026-09-01 14:34 UTCEG score recompute
- 2026-09-01 13:54 UTCEPSS rescore
- 2026-08-31 22:21 UTCEG score recompute
- 2026-08-31 21:25 UTCEG score recompute
- 2026-08-31 21:24 UTCMITRE cvelistV5first tracked
Related CVEs(same CWE)
Same CWE
10 shownCWE-22 · CWE-94
- CVE-2001-1586EG 10.0EPSS p94HIGH
- CVE-2003-1432EG 10.0EPSS p94HIGH
- CVE-2002-0495EG 10.0EPSS p96HIGH
- CVE-1999-0702EG 10.0EPSS p98HIGH
- CVE-1999-0509EG 10.0EPSS p98HIGH
- CVE-2004-0847EG 9.8EPSS p99CRITICAL
- CVE-2002-2269EG 9.4HIGH
- CVE-2004-0273EG 9.3EPSS p90HIGH
- CVE-2004-1364EG 8.5EPSS p96HIGH
- CVE-2002-2233EG 8.3HIGH
Frequently asked(5)
What is CVE-2026-82393?
When was CVE-2026-82393 disclosed?
Is CVE-2026-82393 actively exploited?
What is the CVSS score of CVE-2026-82393?
How do I remediate CVE-2026-82393?
Dependency Blast Radius
Explore the affected products and dependency analysis for CVE-2026-82393
Is Your Infrastructure Affected by CVE-2026-82393?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.