pnpm是pnpm团队开源的一个包管理器。 pnpm 10.34.4之前版本和11.0.0版本至11.7.0之前版本存在安全漏洞,该漏洞源于特制的补丁条目能解析到配置的补丁目录之外,导致pnpm patch-remove删除任意可到达的文件。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59195 | 8.2 HIGH | pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside no |
| CVE-2026-59196 | 7.1 HIGH | pnpm: hoisted install imports lockfile alias outside node_modules |
No comments yet