Zoltan Kochan
9 exploits
Active since Mar 2022
pnpm < 6.15.1 - Untrusted Search Path on Windows
CVSS 8.8
pnpm < 9.15.0 - Untrusted Search Path via Global Cache Override Leak
CVSS 9.8
pnpm < 10.26.0 - Download of Code Without Integrity Check via HTTP Tarball Dependencies
CVSS 7.5
pnpm 10.0.0-10.25 - Remote Code Execution via Git Dependency Lifecycle Scripts
CVSS 8.8
pnpm < 10.28.1 - Path Traversal and Arbitrary File Write via Binary Fetcher
CVSS 6.5
pnpm < 10.28.1 - Path Traversal via Backslash Directory Separator on Windows
CVSS 6.5
pnpm < 10.28.1 - Path Traversal via Bin Linking with Scope Normalization Bypass
CVSS 6.5
pnpm < 10.28.2 - Unauthenticated Arbitrary File Read via Symlink in Local/Git Dependencies
CVSS 6.5
pnpm < 10.28.2 - Arbitrary File Permission Modification via directories.bin Path Traversal
CVSS 5.5