PT-2022-17710 · Pnpm · Pnpm

Zkochan

·

Published

2022-03-21

·

Updated

2023-11-09

·

CVE-2022-26183

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PNPM versions 6.15.1 and below
Description The issue is related to an untrusted search path in PNPM, which can cause the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This occurs when the application is run on Windows OS.
Recommendations For PNPM versions 6.15.1 and below, update to a version above 6.15.1 to resolve the issue. As a temporary workaround, consider avoiding the execution of PNPM commands in directories that may contain malicious content. Restrict access to sensitive directories to minimize the risk of exploitation.

Exploit

Fix

Untrusted Search Path

Weakness Enumeration

Related Identifiers

CVE-2022-26183
GHSA-9M87-6FJ3-C5XH

Affected Products

Pnpm