← العودة للجدول
CVE-2026-82392
CVE-2026-82392 | pnpm up to 10.34.4/11.0.0-11.10.x Lockfile Parser lockfileToDepGraph.ts dp.parse depPath escape output
📅 2026-09-01
🟡 Medium 🔥 No VulDB Vulnerability Vulnerability

📋 الوصف الكامل

A vulnerability categorized as problematic has been discovered in pnpm up to 10.34.4/11.0.0-11.10.x. This affects the function dp.parse of the file deps/graph-builder/src/lockfileToDepGraph.ts of the component Lockfile Parser. The manipulation of the argument depPath results in escaping of output. This vulnerability is reported as CVE-2026-82392. The attack can be launched remotely. No exploit ex

💻 الأنظمة المتأثرة

⚠️ نوع التهديد

Vulnerability

🔗 CVE ID

CVE-2026-82392

📡 المصدر

VulDB

✅ الحلول والتخفيف

Apply vendor security patch

🔗 المصدر الأصلي ← 📘 NVD ← ⚡ CISA KEV ← 🔍 Valters IT ←