Pnpm

Pnpm

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.26%
  • Veröffentlicht 27.09.2026 17:02:33
  • Zuletzt bearbeitet 30.09.2026 17:23:08

pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not validate dependency alias/name paths taken from a lockfile before using them in install-time filesystem joins. When a ...

  • EPSS 0.23%
  • Veröffentlicht 27.09.2026 17:02:33
  • Zuletzt bearbeitet 30.09.2026 17:23:08

pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled ...

  • EPSS 0.41%
  • Veröffentlicht 31.08.2026 21:12:09
  • Zuletzt bearbeitet 09.09.2026 21:09:13

pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json manifest name because pnpm11/resolving/npm-resolver/src/pickPackage.ts rejects slash characters only for unscoped nam...

  • EPSS 0.4%
  • Veröffentlicht 31.08.2026 21:03:25
  • Zuletzt bearbeitet 09.09.2026 21:09:13

pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled pnpm-lock.yaml packages keys with dp.parse(depPath).name and uses it without validation in deps/graph-builder/src/lockfil...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 06.07.2026 15:21:03
  • Zuletzt bearbeitet 07.07.2026 19:09:30

pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious re...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 06.07.2026 15:18:53
  • Zuletzt bearbeitet 07.07.2026 19:09:15

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwr...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 06.07.2026 15:16:28
  • Zuletzt bearbeitet 07.07.2026 19:08:57

pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.

Exploit
  • EPSS 0.33%
  • Veröffentlicht 25.06.2026 17:00:35
  • Zuletzt bearbeitet 29.06.2026 21:16:13

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository co...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 25.06.2026 16:58:57
  • Zuletzt bearbeitet 29.06.2026 20:30:18

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from http...

Exploit
  • EPSS 0.38%
  • Veröffentlicht 25.06.2026 16:56:04
  • Zuletzt bearbeitet 30.06.2026 19:04:10

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. In the reproduced case, the user's npm config contains a default registry...