VulnSea

pnpm vulnerabilities

CVEs whose affected-version data names the pnpm package (npm). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

22 CVEsRSS

GHSA-2rx9-3g3h-c2jvHigh· 7.1
3w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

Twilightpnpm · pnpmvia GHSA
GHSA-vx52-2968-3vc6High· 7.4
3w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

Twilightpnpm · pnpmvia GHSA
CVE-2026-82393High· 7.5
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

Twilightpnpm · pnpmEPSS 0.41%via NVD
CVE-2026-82392High· 7.1
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

Twilightpnpm · pnpmEPSS 0.40%via NVD
GHSA-fr4h-3cph-29xvHigh· 7.1
2mo ago

pnpm: Hoisted install imports lockfile alias outside node_modules

pnpm: Hoisted install imports lockfile alias outside node_modules

Twilightpnpm · pnpmvia GHSA
GHSA-72r4-9c5j-mj57High· 7.1
2mo ago

pnpm: `patch-remove` could delete project-selected files outside the patches directory

pnpm: `patch-remove` could delete project-selected files outside the patches directory

Twilightpnpm · pnpmvia GHSA
GHSA-qrv3-253h-g69cHigh· 8.2
2mo ago

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

Twilightpnpm · pnpmvia GHSA
CVE-2026-48995Medium
2mo ago

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-50573Medium· 6.8
2mo ago

pnpm: Unsafe default behavior breaks integrity check

pnpm: Unsafe default behavior breaks integrity check

Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-50021Medium· 6.8
2mo ago

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

Sunlitpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-50014Medium· 6.4
2mo ago

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

Sunlitpnpm · pnpmEPSS 0.32%via GHSA
CVE-2026-50016High· 8.8
2mo ago

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

Twilightpnpm · pnpmEPSS 0.53%via GHSA
CVE-2026-50017Medium
2mo ago

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

Sunlitpnpm · pnpmEPSS 0.44%via GHSA
CVE-2026-50015High· 7.3
2mo ago

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

Twilightpnpm · pnpmEPSS 0.43%via GHSA
CVE-2026-55180Medium· 6.5
2mo ago

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

Sunlitpnpm · pnpmEPSS 0.37%via GHSA
CVE-2026-55487High· 7.5
2mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

Twilightpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-55697High· 7.5
2mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-55698High· 8.8
2mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

Twilightpnpm · pnpmEPSS 0.30%via GHSA
CVE-2026-55699Medium· 6.5
2mo ago

pnpm: Reserved bin name deletes PNPM_HOME during global remove

pnpm: Reserved bin name deletes PNPM_HOME during global remove

Sunlitpnpm · pnpmEPSS 0.45%via GHSA
CVE-2026-55700High· 7.1
2mo ago

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

Twilightpnpm · pnpmEPSS 0.42%via GHSA
CVE-2025-69264High· 8.8PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Wh…

Midnightpnpm · pnpmEPSS 1.0%via NVD
CVE-2025-69263High· 7.5PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when…

MidnightRed Hat · pnpmEPSS 0.43%via NVD
pnpm vulnerabilities (CVEs) · VulnSea