CNNVD-202601-4325 Information
Jan 26, 2026
cve
CNNVD ID
CNNVD-202601-4325
Related CVE
- CNNVD Published: 2026-01-26
Description (Chinese)
pnpm是pnpm开源的一个包管理器。 pnpm 10.28.1之前版本存在代码问题漏洞,该漏洞源于二进制文件提取器存在路径遍历,可能导致恶意包在预期提取目录外写入文件。
Description (English)
pnpm is a package manager for pnpm open source. There was a code problem loophole in the pre-pnm 10.2.8.1 version, which stemmed from the existence of binary file extractors, which could lead to malicious packages writing files outside the expected extraction directory.
Hazard Level
High
Vulnerability Type
代码问题
Affected Vendor
pnpm
Published
2026-01-26
Last Modified
2026-02-24
References
https://github.com/pnpm/pnpm/commit/5c382f0ca3b7cc49963b94677426e66539dcb3f5 https://github.com/pnpm/pnpm/releases/tag/v10.28.1 https://github.com/pnpm/pnpm/security/advisories/GHSA-6pfh-p556-v868
Patch
https://github.com/pnpm/pnpm/releases
Share on: