Skip to main content
Loading…
    CVE-2023-37478 — pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar ar — CVE Database · The Intelligence Room