CVE-2026-23890 | pnpm up to 10.28.0 path traversal (GHSA-xpqm-wm3m-f34h / EUVD-2026-4656)
A vulnerability was found in pnpm up to 10.28.0. It has been classified as critical. This issue affects some unknown processing. This manipulation causes relative path traversal.
This vulnerability is tracked as CVE-2026-23890. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.