Количество 4
Количество 4
CVE-2026-24131
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package directory, causing pnpm to chmod 755 files at arbitrary locations. This issue only affects Unix/Linux/macOS. Windows is not affected (`fixBin` gated by `EXECUTABLE_SHEBANG_SUPPORTED`). Version 10.28.2 contains a patch.
CVE-2026-24131
pnpm is a package manager. Prior to version 10.28.2, when pnpm process ...
GHSA-v253-rj99-jwpq
pnpm has Path Traversal via arbitrary file permission modification
BDU:2026-01028
Уязвимость функции path.join() менеджера пакетов pnpm, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-24131 pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin": "../../../../tmp"}` to escape the package directory, causing pnpm to chmod 755 files at arbitrary locations. This issue only affects Unix/Linux/macOS. Windows is not affected (`fixBin` gated by `EXECUTABLE_SHEBANG_SUPPORTED`). Version 10.28.2 contains a patch. | CVSS3: 5.5 | 0% Низкий | 9 дней назад | |
CVE-2026-24131 pnpm is a package manager. Prior to version 10.28.2, when pnpm process ... | CVSS3: 5.5 | 0% Низкий | 9 дней назад | |
GHSA-v253-rj99-jwpq pnpm has Path Traversal via arbitrary file permission modification | 0% Низкий | 9 дней назад | ||
BDU:2026-01028 Уязвимость функции path.join() менеджера пакетов pnpm, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации и повысить свои привилегии | CVSS3: 5.5 | 0% Низкий | 14 дней назад |
Уязвимостей на страницу