CVE-2022-26183

Severity CVSS v4.0:
Pending analysis
Type:
CWE-426 Untrusted Search Path
Publication date:
21/03/2022
Last modified:
09/11/2023

Description

PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:* 6.15.1 (excluding)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*