Path traversal in pnpm - CVE-2026-59194
Published: June 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to delete arbitrary files.
The vulnerability exists due to path traversal in patch-remove when processing a crafted patch entry. A remote attacker can supply a crafted patch path that resolves outside the configured patches directory to delete arbitrary files.
User interaction is required to run the pnpm patch-remove command on the crafted entry.