Improper Neutralization of Escape, Meta, or Control Sequences in pnpm - #VU153398
Published: October 6, 2026
Vulnerability details
The vulnerability allows a remote attacker to inject terminal control characters into license table output.
The vulnerability exists due to improper neutralization of terminal control characters in pnpm licenses table rendering when displaying package metadata. A remote attacker can supply package metadata containing terminal control characters to inject terminal control characters into license table output.