pnpm has 21 CVEs on record. Disclosure cadence is accelerating: 20 in the last 90 days against 0 in the 90 before. The busiest recent month was June 2026 with 16. The median CVSS is 7.1 (high). None have a confirmed exploitation report. The dominant weakness classes are CWE-22 (9) and CWE-73 (6).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.1
- Publish → KEV
- —
- Last 90 days
- 20 prev 0
Worst active — by depth score
CVE-2025-69264High· 8.8pnpm is a package manager61CVE-2026-50016High· 8.8pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement49CVE-2026-55698High· 8.8pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes48GHSA-qrv3-253h-g69cHigh· 8.2pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config45GHSA-vx52-2968-3vc6High· 7.4pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml41
pnpm vulnerabilities
CVEs affecting pnpm, newest first. Open any entry for full detail, references, and exploit status.
21 CVEsRSS
GHSA-2rx9-3g3h-c2jvHigh· 7.1pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
GHSA-vx52-2968-3vc6High· 7.4pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
CVE-2026-82393High· 7.5pnpm is a package manager
pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for…
CVE-2026-82392High· 7.1pnpm is a package manager
pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builde…
GHSA-fr4h-3cph-29xvHigh· 7.1pnpm: Hoisted install imports lockfile alias outside node_modules
pnpm: Hoisted install imports lockfile alias outside node_modules
GHSA-72r4-9c5j-mj57High· 7.1pnpm: `patch-remove` could delete project-selected files outside the patches directory
pnpm: `patch-remove` could delete project-selected files outside the patches directory
GHSA-qrv3-253h-g69cHigh· 8.2pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
CVE-2026-48995Mediumpnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
CVE-2026-50573Medium· 6.8pnpm: Unsafe default behavior breaks integrity check
pnpm: Unsafe default behavior breaks integrity check
CVE-2026-50021Medium· 6.8pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2026-50014Medium· 6.4pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVE-2026-50016High· 8.8pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVE-2026-50017Mediumpnpm binds unscoped user-level npm auth credentials to a repository-selected registry
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVE-2026-50015High· 7.3pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-55180Medium· 6.5pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVE-2026-55487High· 7.5pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVE-2026-55697High· 7.5pnpm: Repository-controlled configDependencies can select a pacquet native install engine
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVE-2026-55698High· 8.8pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
CVE-2026-55699Medium· 6.5pnpm: Reserved bin name deletes PNPM_HOME during global remove
pnpm: Reserved bin name deletes PNPM_HOME during global remove
CVE-2026-55700High· 7.1pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
CVE-2025-69264High· 8.8PoCpnpm is a package manager
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". Wh…