pnpm是pnpm团队开源的一个包管理器。 pnpm 10.34.4之前版本和11.0.0至11.7.0之前版本存在安全漏洞,该漏洞源于特制的lockfile别名可被直接连接到提升的node_modules目录下,遍历别名可能导致绕过目录限制,而.bin或.pnpm等保留别名可能覆盖pnpm自有布局。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-59195 | 8.2 HIGH | pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside no |
| CVE-2026-59194 | 7.1 HIGH | pnpm: patch-remove could delete project-selected files outside the patches directory |
No comments yet