HIGH 8.8 npm

Untrusted Search Path in PNPM

GHSA-9m87-6fj3-c5xh · CVE-2022-26183

Published · Modified

AI SAST

Find this class of vulnerability in your own code

Corgea's AI-native static analysis detects vulnerabilities like this one across your repositories, ranks them by exploitability, and returns review-ready fixes.

Description

PNPM prior to v6.15.1 was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Ready to move

Start Securing

Free, no credit card | First findings in minutes