{"id":"GHSA-72r4-9c5j-mj57","title":"pnpm: `patch-remove` could delete project-selected files outside the patches directory","summary":"pnpm: `patch-remove` could delete project-selected files outside the patches directory","severity":"high","cvss":7.1,"cwe":["CWE-22","CWE-73"],"vendor":"pnpm","product":"pnpm","ecosystem":"npm","affected":["pnpm < 10.34.4","pnpm >= 11.0.0, < 11.7.0"],"patched":["pnpm 10.34.4","pnpm 11.7.0"],"published":"2026-06-27","updated":"2026-06-27","source":"GHSA","sourceUrl":"https://github.com/advisories/GHSA-72r4-9c5j-mj57","references":[{"url":"https://github.com/pnpm/pnpm/security/advisories/GHSA-72r4-9c5j-mj57"},{"url":"https://github.com/pnpm/pnpm/commit/612a2e6a7333f2b061f452a21b6e62c1c161747f"},{"url":"http://github.com/pnpm/pnpm/commit/352ae489f1b14ffdc19d2c6eacb1b06b098c2ddc"},{"url":"https://github.com/advisories/GHSA-72r4-9c5j-mj57"}],"tags":["ghsa","npm"],"ingestedAt":"2026-06-29T13:24:35.053Z","slug":"GHSA-72r4-9c5j-mj57","body":"## Overview\n\n## Summary\n\nThe `patch-remove` deletion-scope issue tracked as GHSA-72r4-9c5j-mj57 / CAND-PNPM-030 has been addressed in pnpm.\n\nA crafted patch entry could resolve outside the configured patches directory and cause `pnpm patch-remove` to delete an arbitrary reachable file. This patch validates the configured directory and every resolved target before unlinking anything, then deletes the final directory entry without following it.\n\n## Security boundary\n\n- Traversal and absolute paths that resolve outside the configured patches directory are rejected before deletion.\n- Parent directories are canonicalized before deletion, including the case where a nested symlink points outside and the final outside entry is itself dangling.\n- The complete batch is validated before any file is removed.\n- Component-aware predicates accept valid names beginning with `..` while still rejecting parent traversal, Windows drive escapes, and UNC escapes.\n- Valid files and symlinked patch directories whose canonical targets remain below the lockfile directory continue to work.\n- A final symlink inside a valid patch directory is unlinked without following its target, including when the target is outside or dangling.\n\n## Exploit replay\n\nBefore the patch, a workspace `patchedDependencies` path that resolved outside the project caused `pnpm patch-remove` to delete the external sentinel. A second replay used a nested parent symlink and a dangling outside victim: `realpath()` returned `ENOENT`, yet the victim was still removed. With this patch, both paths are rejected and the outside entries remain intact.\n\n## Files changed\n\n- `patching/commands/src/isSubdirectory.ts` performs component-aware containment checks.\n- `patching/commands/src/patchRemove.ts` validates the full batch, canonicalizes parents, and unlinks final entries without following them.\n- `patching/commands/test/{isSubdirectory,patchRemove}.test.ts` covers traversal, nested symlinks, dangling victims, and valid removals.\n\n## Commands run\n\n```text\n$ pnpm --filter @pnpm/patching.commands test test/isSubdirectory.test.ts test/patchRemove.test.ts\nPASS: 11 tests across 2 suites\n$ pnpm --filter @pnpm/patching.commands run compile\nPASS\n$ git diff --check\nPASS\n```\n\n## Validation\n\n- Focused handler and path-predicate suites: 11 passed across 2 suites.\n- Package-wide ESLint: passed.\n- Package TypeScript build: passed.\n- Commit hooks, Commitlint, and `git diff --check`: passed.\n- The broader integration harness was environment-blocked because it writes outside the available temporary root; focused handler tests used `/private/tmp`.\n\n## Patches\n\n`10.34.4`: https://github.com/pnpm/pnpm/commit/352ae489f1b14ffdc19d2c6eacb1b06b098c2ddc\n`11.7.0`: https://github.com/pnpm/pnpm/commit/612a2e6a7333f2b061f452a21b6e62c1c161747f\n\n## Compatibility\n\nMissing patch files remain no-ops. Valid symlinked patch directories continue to work when their canonical target stays inside the lockfile directory, and final symlinks are removed without touching their targets. `patch-remove` is not yet in pacquet's command surface, so no Rust-side parity change is required.\n\n## Remaining risk\n\nPortable Node APIs do not expose directory-fd-relative `unlinkat()`. A local attacker who can replace an already validated parent directory before the unlink may still win a time-of-check/time-of-use race. The reproduced repository-controlled traversal and symlink paths do not require that concurrent capability and are blocked by this patch.\n\n---\nWritten by an agent (Codex, GPT-5).\n\n## Affected packages\n\n- `pnpm < 10.34.4`\n- `pnpm >= 11.0.0, < 11.7.0`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pnpm 10.34.4`\n- `pnpm 11.7.0`","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}