CyberRota Analysis
AI-GeneratedA vulnerability in pnpm allows a crafted patch entry to resolve outside the designated patches directory, potentially enabling the `pnpm patch-remove` command to delete arbitrary files on the system. This poses a significant risk to users of versions prior to 10.34.4 and 11.7.0, particularly those managing critical applications or sensitive data. Organizations utilizing pnpm should prioritize upgrading to the patched versions to mitigate the risk of unauthorized file deletion.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
Related CVEs
Other vulnerabilities affecting the same vendor(s)