CVE-2022-26183: High severity pnpm vulnerability
PNPM prior to v6.15.1 was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.
Other sources
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-26183?
The severity of CVE-2022-26183 is classified as high due to its potential to allow execution of arbitrary code.
How do I fix CVE-2022-26183?
To fix CVE-2022-26183, upgrade PNPM to version 6.15.1 or later.
What systems are affected by CVE-2022-26183?
CVE-2022-26183 affects PNPM versions prior to 6.15.1 when run on Windows operating systems.
What causes the vulnerability in CVE-2022-26183?
CVE-2022-26183 is caused by an untrusted search path that leads to unexpected behavior when executing PNPM commands in compromised directories.
Can CVE-2022-26183 be exploited remotely?
CVE-2022-26183 requires local access to a compromised directory, making it not directly exploitable remotely.