StackRadar

CVE-2026-23889

Medium

Advisory

Published 26 Jan 2026In the index since 5 Sept 2026
Severity
Medium
worst across findings
CVSS
6.5
base score, highest
EPSS
0.004
37th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
24
of 17,781 indexed, latest versions
Container images
25
deployed by those charts
Fix available
1 of 1
affected package

pnpm has Windows-specific tarball Path Traversal

Carried by container images the latest versions of 24 of 17,781 indexed charts deploy, on 25 images.

Affected packageAffected versionsFixed inImages
pnpmnpm7.28.0, 8.3.1, 8.10.2, 8.15.1+16 more10.28.125
OSV records
GHSA-6x96-7vc8-cm3p

Charts affected

24 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
pnpm@10.22.0
10.28.1

Open the chart page →

19,391
umamichristianhuthVerified publisher7.13.01 of 2See more

umami christianhuth 7.13.0

1 of the 2 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
pnpm@10.24.0
10.28.1

Open the chart page →

2,367
syftopenmined0.9.51 of 6See more

syft openmined 0.9.5

1 of the 6 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
openmined/syft-frontend:0.9.5d11524a3854a
pnpm@10.3.0
10.28.1

Open the chart page →

17,245
docmosthelmforgeVerified publisher1.2.111 of 4See more

docmost helmforge 1.2.11

1 of the 4 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
docmost/docmost:0.95.041c8d777cf23
pnpm@10.4.0
10.28.1

Open the chart page →

5,564
hoppscotchdeliveryheroVerified publisher0.3.21 of 1See more

hoppscotch deliveryhero 0.3.2

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
pnpm@9.10.0
10.28.1

Open the chart page →

3,451
activepiecesmeyerchartsVerified publisher0.1.61 of 1See more

activepieces meyercharts 0.1.6

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
activepieces/activepieces:0.23.0c26188b44e62
pnpm@7.28.0
10.28.1

Open the chart page →

2,635
litlyxlitlyx0.2.02 of 5See more

litlyx litlyx 0.2.0

2 of the 5 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
litlyx/litlyx-consumer:latest02225e77d316
pnpm@10.23.0
10.28.1
litlyx/litlyx-producer:latest10407f36613f
pnpm@10.23.0
10.28.1

Open the chart page →

7,874
peertubepeertubeVerified publisher0.1.31 of 1See more

peertube peertube 0.1.3

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
chocobozzz/peertube:v8.1.5052712130691
pnpm@10.15.1
10.28.1

Open the chart page →

7,035
jellyseerrrtomik-helm-chartsVerified publisher0.0.11 of 1See more

jellyseerr rtomik-helm-charts 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
pnpm@9.15.9
10.28.1

Open the chart page →

2,823
astrotrekastria0.0.21 of 4See more

astrotrek astria 0.0.2

1 of the 4 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
pnpm@9.10.0
10.28.1

Open the chart page →

32,501
nas-appsawesomeVerified publisher2.0.01 of 8See more

nas-apps awesome 2.0.0

1 of the 8 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
wettyoss/wetty:latest7423b3d40ba2
pnpm@9.15.9
10.28.1

Open the chart page →

7,152
cloudpremcloudprem0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad2 of 6See more

cloudprem cloudprem 0.0.0-build.00306ba7288bb8d46dd8c6190af79ef5b6fbdbad

2 of the 6 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
pnpm@10.17.0
10.28.1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
pnpm@10.17.0
10.28.1

Open the chart page →

18,293
dev-code-servercosmoVerified publisher0.0.71 of 2See more

dev-code-server cosmo 0.0.7

1 of the 2 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pnpm@10.8.0
10.28.1

Open the chart page →

14,559
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
pnpm@9.12.2
10.28.1

Open the chart page →

19,224
consent-managerfiware0.1.21 of 1See more

consent-manager fiware 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
quay.io/wi_stefan/consent-manager:0.0.656399619568b
pnpm@8.15.9
10.28.1

Open the chart page →

1,847
hoppscotchhelm-charts-nr0.3.11 of 1See more

hoppscotch helm-charts-nr 0.3.1

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.8.2f1da831950b7
pnpm@9.10.0
10.28.1

Open the chart page →

3,451
hoppscotchhoppscotch0.1.11 of 1See more

hoppscotch hoppscotch 0.1.1

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
pnpm@9.14.2
10.28.1

Open the chart page →

3,614
component-storekubebb0.0.231 of 1See more

component-store kubebb 0.0.23

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
kubebb/component-store:latestfd8ecbd73213
pnpm@8.15.1
10.28.1

Open the chart page →

2,178
u4a-componentkubebb0.2.101 of 8See more

u4a-component kubebb 0.2.10

1 of the 8 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
kubebb/bff-server:v0.2.0-202312040fbb732379bc
pnpm@8.10.2
10.28.1

Open the chart page →

13,819
jellyseerrlbenicio-communityVerified publisher0.1.01 of 1See more

jellyseerr lbenicio-community 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
fallenbagel/jellyseerr:latest4538137bc5af
pnpm@9.15.9
10.28.1

Open the chart page →

3,555
hyperglassm0nsterrr-hyperglassVerified publisher4.2.11 of 2See more

hyperglass m0nsterrr-hyperglass 4.2.1

1 of the 2 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pnpm@9.5.0
10.28.1

Open the chart page →

4,647
magistralamagistrala-devopsVerified publisher0.16.21 of 42See more

magistrala magistrala-devops 0.16.2

1 of the 42 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
pnpm@10.12.1
10.28.1

Open the chart page →

24,400
tianjimsgbyte0.1.171 of 2See more

tianji msgbyte 0.1.17

1 of the 2 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
moonrailgun/tianji:1.11.2b528c8f8fcc4
pnpm@8.3.1
10.28.1

Open the chart page →

4,560
umamimt1905028.1.41 of 3See more

umami mt190502 8.1.4

1 of the 3 container images this version deploys carry CVE-2026-23889.

Container imageDigestPackageFixed in
ghcr.io/umami-software/umami:3.0.328f263fe06f7
pnpm@10.25.0
10.28.1

Open the chart page →

4,016

Container images carrying it

25 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
hoppscotch/hoppscotch:2024.8.2f1da831950b7
pnpm@9.10.0
10.28.1
2
activepieces/activepieces:0.23.0c26188b44e62
pnpm@7.28.0
10.28.1
1
chocobozzz/peertube:v8.1.5052712130691
pnpm@10.15.1
10.28.1
1
docmost/docmost:0.95.041c8d777cf23
pnpm@10.4.0
10.28.1
1
fallenbagel/jellyseerr:latest4538137bc5af
pnpm@9.15.9
10.28.1
1
hoppscotch/hoppscotch:2024.11.0538fe6ded4b6
pnpm@9.14.2
10.28.1
1
kubebb/bff-server:v0.2.0-202312040fbb732379bc
pnpm@8.10.2
10.28.1
1
kubebb/component-store:latestfd8ecbd73213
pnpm@8.15.1
10.28.1
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
pnpm@10.22.0
10.28.1
1
langgenius/dify-web:1.0.0d64914ff0d6d
pnpm@9.12.2
10.28.1
1
litlyx/litlyx-consumer:latest02225e77d316
pnpm@10.23.0
10.28.1
1
litlyx/litlyx-producer:latest10407f36613f
pnpm@10.23.0
10.28.1
1
moonrailgun/tianji:1.11.2b528c8f8fcc4
pnpm@8.3.1
10.28.1
1
openmined/syft-frontend:0.9.5d11524a3854a
pnpm@10.3.0
10.28.1
1
wettyoss/wetty:latest7423b3d40ba2
pnpm@9.15.9
10.28.1
1
ghcr.io/absmach/magistrala/ui-smq:latestea7e7f0e293e
pnpm@10.12.1
10.28.1
1
ghcr.io/astriaorg/astrotrek:0.1.05889bea38e56
pnpm@9.10.0
10.28.1
1
ghcr.io/cosmo-workspace/dev-code-server:v0.0.316fda01ae58a
pnpm@10.8.0
10.28.1
1
ghcr.io/fallenbagel/jellyseerr:2.5.22a611369ad1d
pnpm@9.15.9
10.28.1
1
ghcr.io/formancehq/console-v3:v1.16.0c99e8ef2c545
pnpm@10.17.0
10.28.1
1
ghcr.io/formancehq/portal:v1.16.06efef5d19d56
pnpm@10.17.0
10.28.1
1
ghcr.io/m0nsterrr/hyperglass:v2.0.4f7b5d20c5e42
pnpm@9.5.0
10.28.1
1
ghcr.io/umami-software/umami:3.0.328f263fe06f7
pnpm@10.25.0
10.28.1
1
ghcr.io/umami-software/umami:postgresql-v2.20.173ca19b41745
pnpm@10.24.0
10.28.1
1
quay.io/wi_stefan/consent-manager:0.0.656399619568b
pnpm@8.15.9
10.28.1
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.