VulnSea

pnpm has 21 CVEs on record. Disclosure cadence is accelerating: 20 in the last 90 days against 0 in the 90 before. The busiest recent month was June 2026 with 16. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (9) and CWE-73 (6).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.1
Publish → KEV
Last 90 days
20 prev 0

Products

  • pnpm 21
21
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

pnpm vulnerabilities

CVEs affecting pnpm, newest first. Open any entry for full detail, references, and exploit status.

21 CVEsRSS

GHSA-2rx9-3g3h-c2jvHigh· 7.1
3w ago

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project

Twilightpnpm · pnpmvia GHSA
GHSA-vx52-2968-3vc6High· 7.4
3w ago

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml

Twilightpnpm · pnpmvia GHSA
CVE-2026-82393High· 7.5
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…

Twilightpnpm · pnpmEPSS 0.41%via NVD
CVE-2026-82392High· 7.1
3w ago

pnpm is a package manager

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…

Twilightpnpm · pnpmEPSS 0.40%via NVD
GHSA-fr4h-3cph-29xvHigh· 7.1
2mo ago

pnpm: Hoisted install imports lockfile alias outside node_modules

pnpm: Hoisted install imports lockfile alias outside node_modules

Twilightpnpm · pnpmvia GHSA
GHSA-72r4-9c5j-mj57High· 7.1
2mo ago

pnpm: `patch-remove` could delete project-selected files outside the patches directory

pnpm: `patch-remove` could delete project-selected files outside the patches directory

Twilightpnpm · pnpmvia GHSA
GHSA-qrv3-253h-g69cHigh· 8.2
2mo ago

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

Twilightpnpm · pnpmvia GHSA
CVE-2026-48995Medium
2mo ago

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-50573Medium· 6.8
2mo ago

pnpm: Unsafe default behavior breaks integrity check

pnpm: Unsafe default behavior breaks integrity check

Sunlitpnpm · pnpmEPSS 0.17%via GHSA
CVE-2026-50021Medium· 6.8
2mo ago

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

Sunlitpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-50014Medium· 6.4
2mo ago

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

Sunlitpnpm · pnpmEPSS 0.32%via GHSA
CVE-2026-50016High· 8.8
2mo ago

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

Twilightpnpm · pnpmEPSS 0.53%via GHSA
CVE-2026-50017Medium
2mo ago

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

Sunlitpnpm · pnpmEPSS 0.44%via GHSA
CVE-2026-50015High· 7.3
2mo ago

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

Twilightpnpm · pnpmEPSS 0.43%via GHSA
CVE-2026-55180Medium· 6.5
2mo ago

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

Sunlitpnpm · pnpmEPSS 0.37%via GHSA
CVE-2026-55487High· 7.5
2mo ago

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

Twilightpnpm · pnpmEPSS 0.18%via GHSA
CVE-2026-55697High· 7.5
2mo ago

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

Twilightpnpm · pnpmEPSS 0.19%via GHSA
CVE-2026-55698High· 8.8
2mo ago

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

Twilightpnpm · pnpmEPSS 0.30%via GHSA
CVE-2026-55699Medium· 6.5
2mo ago

pnpm: Reserved bin name deletes PNPM_HOME during global remove

pnpm: Reserved bin name deletes PNPM_HOME during global remove

Sunlitpnpm · pnpmEPSS 0.45%via GHSA
CVE-2026-55700High· 7.1
2mo ago

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

Twilightpnpm · pnpmEPSS 0.42%via GHSA
CVE-2025-69264High· 8.8PoC
8mo ago

pnpm is a package manager

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Wh…

Midnightpnpm · pnpmEPSS 1.0%via NVD
pnpm vulnerabilities (CVEs) · VulnSea