PT-2026-55946 · Npm · Pnpm
CVSS v3.1
7.1
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
pnpm versions prior to 10.34.4
pnpm versions prior to 11.7.0
Description
A crafted patch entry can resolve outside the configured patches directory, allowing the
pnpm patch-remove command to delete an arbitrary reachable file.Recommendations
Update to version 10.34.4 or later.
Update to version 11.7.0 or later.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pnpm