VYPR
High severity7.1OSV Advisory· Published Jul 6, 2026· Updated Jul 7, 2026

CVE-2026-59194

CVE-2026-59194

Description

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.

Affected products

3
  • Pnpm/PnpmOSV3 versions
    v11.6.0, v10.34.3, v10.34.2, …+ 2 more
    • (no CPE)range: v11.6.0, v10.34.3, v10.34.2, …
    • cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*range: <10.34.4
    • (no CPE)range: <10.34.4, <11.7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.