VYPR
Unrated severityOSV Advisory· Published Jul 6, 2026· Updated Jul 6, 2026

pnpm: hoisted install imports lockfile alias outside node_modules

CVE-2026-59196

Description

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixed in 10.34.4 and 11.7.0.

Affected products

2
  • Pnpm/PnpmOSV2 versions
    v11.6.0, v10.34.3, v10.34.2, …+ 1 more
    • (no CPE)range: v11.6.0, v10.34.3, v10.34.2, …
    • (no CPE)range: <10.34.4, <11.7.0

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.