ZeroHour

CVE-2022-26183

PoC
CVSS 3.1
8.8 high
EPSS
2%p74
Published
()
Modified
Description

PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Vendors
pnpm
Products
pnpm
Weakness
CWE-426
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.