AUGUST 24, 2026
Live Feed
Back to database
Case File

CVE-2026-59194

HIGH · CVSS 7.1 EPSS 0.29% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-06 · Last synced 2026-08-05

CyberRota Analysis

AI-Generated

A vulnerability in pnpm allows a crafted patch entry to resolve outside the designated patches directory, potentially enabling the `pnpm patch-remove` command to delete arbitrary files on the system. This poses a significant risk to users of versions prior to 10.34.4 and 11.7.0, particularly those managing critical applications or sensitive data. Organizations utilizing pnpm should prioritize upgrading to the patched versions to mitigate the risk of unauthorized file deletion.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-59194
Severity
HIGH
CVSS
7.1
EPSS
0.29%

Original NVD Description

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)