Skip to main content
Loading…
    CVE-2026-24131 — pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A m — CVE Database · The Intelligence Room