All intelligence
// vulnerability record
cached · NVD via COSMOS syncCVE-2026-55699
MEDIUMpublished 2026-06-25 18:16 UTC · 3 days ago · modified 2026-06-25 19:16 UTC
6.5
CVSS / 10
// description
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows could re-derive those names from the installed manifest and pass path.join(globalBinDir, binName) to removeBin. For "." this targets the global bin directory; for ".." this targets its parent. This vulnerability is fixed in 10.34.2 and 11.5.3.
// cvss 3.1 vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
// weaknesses (CWE)
- CWE-22
- CWE-73