Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-50015

Опубликовано: 25 июн. 2026
Источник: nvd
CVSS3: 7.3
EPSS Низкий

Описание

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull request can write attacker-controlled content to or delete arbitrary files on the filesystem during pnpm install, as the user running the install. The diff --git header paths containing ../../ sequences traverse out of the package directory, and the traversal is difficult to catch in code review because patch file diff headers are opaque to most reviewers. This vulnerability is fixed in 10.34.0 and 11.4.0.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*
Версия до 10.34.0 (исключая)
cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*
Версия от 11.0.0 (включая) до 11.4.0 (исключая)

EPSS

Процентиль: 29%
0.00365
Низкий

7.3 High

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 7.3
redhat
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull request can write attacker-controlled content to or delete arbitrary files on the filesystem during pnpm install, as the user running the install. The diff --git header paths containing ../../ sequences traverse out of the package directory, and the traversal is difficult to catch in code review because patch file diff headers are opaque to most reviewers. This vulnerability is fixed in 10.34.0 and 11.4.0.

CVSS3: 7.3
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch a ...

CVSS3: 7.3
github
около 1 месяца назад

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

EPSS

Процентиль: 29%
0.00365
Низкий

7.3 High

CVSS3

Дефекты

CWE-22