CVE-2026-59196: pnpm: hoisted install imports lockfile alias outside node_modules
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted nodemodules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwrite pnpm-owned layout. This vulnerability is fixed in 10.34.4 and 11.7.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pnpmto a version that resolves this vulnerability.Fixed in 10.34.4 - Upgrade
Upgrade
pnpmto a version that resolves this vulnerability.Fixed in 11.7.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-59196?
The severity of CVE-2026-59196 is rated as high with a score of 7.1.
How do I fix CVE-2026-59196?
To fix CVE-2026-59196, upgrade pnpm to version 10.34.4 or later, or 11.7.0 or later.
What type of vulnerability is CVE-2026-59196?
CVE-2026-59196 is classified as a Path Traversal vulnerability.
Which package manager is affected by CVE-2026-59196?
The package manager affected by CVE-2026-59196 is pnpm.
When was CVE-2026-59196 published?
CVE-2026-59196 was published on July 6, 2026.