CVE-2026-59194
pnpm
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
- CVSS
- 7.1
- EPSS
- 0.26% 17.1% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.07