Skip to content

Commit af6d4cb

Browse files
committed
Fix security issue: prevent patching global pnpm store with relative cwd
When --cwd is '.', normalize_lexically returns an empty PathBuf, which causes strip_prefix to succeed for any path including absolute global stores. This fix adds a check to reject empty importer paths, preventing accidental patching of shared global stores used by other projects.
1 parent 4e88251 commit af6d4cb

1 file changed

Lines changed: 8 additions & 1 deletion

File tree

‎crates/socket-patch-core/src/crawlers/npm_crawler.rs‎

Lines changed: 8 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -310,6 +310,9 @@ fn relocated_pnpm_virtual_store_sync(nm: &Path) -> Option<PathBuf> {
310310
let text = crate::utils::fs::read_regular_to_string_sync(&nm.join(PNPM_MODULES_YAML)).ok()?;
311311
let recorded = parse_modules_yaml_virtual_store_dir(&text)?;
312312
let importer = normalize_lexically(nm.parent()?);
313+
if importer.as_os_str().is_empty() {
314+
return None;
315+
}
313316
let store = normalize_lexically(&nm.join(recorded));
314317
if store == normalize_lexically(&nm.join(".pnpm")) || store == normalize_lexically(nm) {
315318
return None;
@@ -1088,7 +1091,11 @@ impl NpmCrawler {
10881091
/// Inside a store entry (`store_entry`) a link is a dependency edge into
10891092
/// a sibling entry, whose own visit records that copy, so only a real
10901093
/// directory there matches.
1091-
fn visit_resolver_dir(nm_path: PathBuf, store_entry: bool, pending: &[Target]) -> ResolverVisit {
1094+
fn visit_resolver_dir(
1095+
nm_path: PathBuf,
1096+
store_entry: bool,
1097+
pending: &[Target],
1098+
) -> ResolverVisit {
10921099
let listing = list_dir_sync(&nm_path);
10931100
let probe_filter = ProbeFilter::new(&listing);
10941101
let matched = pending

0 commit comments

Comments
 (0)