High severity7.1OSV Advisory· Published Jul 6, 2026· Updated Jul 7, 2026
CVE-2026-59194
CVE-2026-59194
Description
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
Affected products
3Patches
Vulnerability mechanics
References
1- github.com/pnpm/pnpm/security/advisories/GHSA-72r4-9c5j-mj57nvdVendor AdvisoryExploit
News mentions
0No linked articles in our index yet.