CVE-2022-26183: High severity pnpm vulnerability

Published Mar 21, 2022
·
Updated

PNPM prior to v6.15.1 was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Other sources

PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the application is ran on Windows OS.

Affected Software

4 affected componentsFixes available
npm/pnpm<6.15.1
6.15.1
PNPM Pnpm Node.js<6.15.1
Microsoft Windows
PNPM PNPM<=6.15.1

Event History

Mar 21, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Mar 23, 2022
Advisory Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2022-26183?

The severity of CVE-2022-26183 is classified as high due to its potential to allow execution of arbitrary code.

2

How do I fix CVE-2022-26183?

To fix CVE-2022-26183, upgrade PNPM to version 6.15.1 or later.

3

What systems are affected by CVE-2022-26183?

CVE-2022-26183 affects PNPM versions prior to 6.15.1 when run on Windows operating systems.

4

What causes the vulnerability in CVE-2022-26183?

CVE-2022-26183 is caused by an untrusted search path that leads to unexpected behavior when executing PNPM commands in compromised directories.

5

Can CVE-2022-26183 be exploited remotely?

CVE-2022-26183 requires local access to a compromised directory, making it not directly exploitable remotely.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203