Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-qrv3-253h-g69c
  • npm/pnpm
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config 27 Jun
  • Fix available
  • Severity - 8.2 (High)
ROOT-APP-NPM-GHSA-qrv3-253h-g69c
  • Root:npm/@rootio/pnpm
  • Root:npm/pnpm
GHSA-qrv3-253h-g69c in @rootio/pnpm - Patched by Root 30 Jul
  • Fix available
CVE-2026-59195
  • github.com/pnpm/pnpm
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config 06 Jul
  • Fix available
  • Severity - 8.2 (High)
CGA-7mp9-fgvx-vvhh
  • Chainguard/pnpm-stage0
  • Wolfi/pnpm-stage0
See record for full details 28 Jun
  • No fix available
  • Severity - 8.2 (High)
CGA-wmh6-69m8-vv8q
  • Chainguard/pnpm-stage0
  • Wolfi/pnpm-stage0
See record for full details 27 Jun
  • No fix available
  • Severity - 8.2 (High)