pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias
Published Sep 27, 2026
7.1
HIGHCVSS 4.0
EPSS 0.26%
Description
pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a user installs a project with an attacker-supplied lockfile using --trust-lockfile or a frozen lockfile, alias entries containing path traversal segments (for example '../../escaped-link') are used when creating dependency and package links, bin destinations, hoisted entries, and virtual-store slots, allowing symlinks and directories to be created outside the intended project and node_modules boundary. Version 12.0.0-alpha.5 validates dependency names and every virtual-store slot path with a shared safe-join containment helper before any filesystem materialization, rejecting traversal, absolute, platform-specific, and reserved names with ERR_PNPM_INVALID_DEPENDENCY_NAME.
Affected products
-
- Version 12.0.0-alpha.0StatusaffectedConstraints<12.0.0-alpha.5
- Version 12.0.0-alpha.5StatusunaffectedConstraints-
- Version
No data.
No data.
Red Hat AMQ Broker 7
amq-broker-bin.zip
Not affected
Red Hat AMQ Broker 7
amq-broker-maven-repository.zip
Affected
Red Hat Build of Keycloak
keycloak-operator.redhat-00001.zip
Affected
Red Hat Build of Keycloak
keycloak-operator.redhat-00003.zip
Affected
Red Hat Build of Keycloak
rhbk-quarkus-dist.zip
Affected
Red Hat Hardened Images
jaeger
Not affected
Red Hat Hardened Images
prometheus3.13
Not affected
Red Hat JBoss Enterprise Application Platform 8
jboss-eap-runtime-maven-repository.zip
Affected
Red Hat JBoss Enterprise Application Platform 8
jboss-eap.1-runtime-maven-repository.zip
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jboss-eap-runtime-maven-repository.zip
Affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
jboss-eap.1-runtime-maven-repository.zip
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Broker 7 | amq-broker-bin.zip | Not affected | n/a |
| Red Hat AMQ Broker 7 | amq-broker-maven-repository.zip | Affected | n/a |
| Red Hat Build of Keycloak | keycloak-operator.redhat-00001.zip | Affected | n/a |
| Red Hat Build of Keycloak | keycloak-operator.redhat-00003.zip | Affected | n/a |
| Red Hat Build of Keycloak | rhbk-quarkus-dist.zip | Affected | n/a |
| Red Hat Hardened Images | jaeger | Not affected | n/a |
| Red Hat Hardened Images | prometheus3.13 | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jboss-eap-runtime-maven-repository.zip | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | jboss-eap.1-runtime-maven-repository.zip | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jboss-eap-runtime-maven-repository.zip | Affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | jboss-eap.1-runtime-maven-repository.zip | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
NoneAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Sep 30, 2026 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
Percentile over time
Not enough EPSS history yet for a chart. At least two recorded scores are needed.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-101044 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2542140 Issue Tracking
- https://github.com/pnpm/pnpm/security/advisories/GHSA-2rx9-3g3h-c2jv vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-101044
- https://www.cve.org/CVERecord?id=CVE-2026-101044
- https://www.vulncheck.com/advisories/pacquet-before-12.0.0-alpha.5-path-traversal-via-lockfile-alias third-party-advisory
Change history (0)
No recorded changes yet.