Skip to main content
Loading…
    CVE-2026-24056 — pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the — CVE Database · The Intelligence Room