CVE-2026-82392 | pnpm up to 10.34.4/11.0.0-11.10.x Lockfile Parser lockfileToDepGraph.ts dp.parse depPath escape output

SecurityVulns

A vulnerability categorized as problematic has been discovered in pnpm up to 10.34.4/11.0.0-11.10.x. This affects the function dp.parse of the file deps/graph-builder/src/lockfileToDepGraph.ts of the component Lockfile Parser. The manipulation of the argument depPath results in escaping of output.

This vulnerability is reported as CVE-2026-82392. The attack can be launched remotely. No exploit exists.

It is advisable to upgrade the affected component.VulDB Recent EntriesRead More