Pnpm

Pnpm

25 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS -
  • Veröffentlicht 25.06.2026 17:00:35
  • Zuletzt bearbeitet 25.06.2026 19:16:42

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository co...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:58:57
  • Zuletzt bearbeitet 26.06.2026 04:17:44

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from http...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:56:04
  • Zuletzt bearbeitet 25.06.2026 18:58:05

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. In the reproduced case, the user's npm config contains a default registry...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:53:16
  • Zuletzt bearbeitet 25.06.2026 19:16:39

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependen...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:52:01
  • Zuletzt bearbeitet 25.06.2026 19:16:39

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull reque...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:51:16
  • Zuletzt bearbeitet 25.06.2026 19:16:39

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a ma...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:50:21
  • Zuletzt bearbeitet 25.06.2026 19:16:39

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. When a package is alr...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:48:27
  • Zuletzt bearbeitet 26.06.2026 04:17:44

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolution. If an attacker can both modify pnpm-lock.yaml to remove the integri...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:47:21
  • Zuletzt bearbeitet 25.06.2026 19:16:43

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite another reacha...

  • EPSS -
  • Veröffentlicht 25.06.2026 16:44:32
  • Zuletzt bearbeitet 25.06.2026 19:16:43

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows could re-d...