CVE-2026-82393 | pnpm up to 10.34.4/11.10.x Npm Resolver pickPackage.ts path traversal
A vulnerability was found in pnpm up to 10.34.4/11.10.x. It has been declared as critical. This impacts an unknown function of the file pnpm11/resolving/npm-resolver/src/pickPackage.ts of the component Npm Resolver. The manipulation results in path traversal.
This vulnerability is cataloged as CVE-2026-82393. The attack may be launched remotely. There is no exploit available.
It is recommended to upgrade the affected component.VulDB Recent EntriesRead More