CVE-2026-23889 | pnpm up to 10.28.0 on Windows path traversal (GHSA-6x96-7vc8-cm3p / EUVD-2026-4657)
A vulnerability was found in pnpm up to 10.28.0 on Windows and classified as critical. This vulnerability affects unknown code. The manipulation results in path traversal.
This vulnerability is identified as CVE-2026-23889. The attack can be executed remotely. There is not any exploit available.
It is suggested to upgrade the affected component.