Bugzilla – Bug 1271083
VUL-0: CVE-2026-59194: pnpm: patch-remove could delete project-selected files outside the patches directory
Last modified: 2026-07-09 03:15:05 UTC
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0. References: http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2026-59194 https://www.cve.org/CVERecord?id=CVE-2026-59194 https://github.com/pnpm/pnpm/security/advisories/GHSA-72r4-9c5j-mj57 https://github.com/CVEProject/cvelistV5/blob/main//cves/2026/59xxx/CVE-2026-59194.json https://bugzilla.redhat.com/show_bug.cgi?id=2497373
Tracking as affected: openSUSE:Backports:SLE-16.0/pnpm pnpm (10.22.0)