Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-59194

Опубликовано: 06 июл. 2026
Источник: redhat
CVSS3: 7.1
EPSS Низкий

Описание

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.

A flaw was found in pnpm, a package manager. A remote attacker could exploit this vulnerability by providing a specially crafted patch entry. This crafted entry could resolve outside the configured patches directory, allowing for the deletion of an arbitrary file when pnpm patch-remove is executed. This could lead to data integrity issues or a denial of service.

Отчет

This is an Important flaw in pnpm where a crafted patch entry can enable arbitrary file deletion. When the pnpm patch-remove command processes such an entry, it may resolve paths outside the intended patches directory, allowing the deletion of arbitrary files. While the primary issue is addressed by validating paths, a local attacker could still exploit a time-of-check/time-of-use race condition to achieve similar effects.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-22
https://bugzilla.redhat.com/show_bug.cgi?id=2497373pnpm: pnpm: patch-remove could delete project-selected files outside the patches directory

EPSS

Процентиль: 21%
0.00287
Низкий

7.1 High

CVSS3

Связанные уязвимости

CVSS3: 7.1
nvd
28 дней назад

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.

CVSS3: 7.1
debian
28 дней назад

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patc ...

EPSS

Процентиль: 21%
0.00287
Низкий

7.1 High

CVSS3