CVE-2026-59195
- EPSS 0.29%
- Veröffentlicht 06.07.2026 15:21:03
- Zuletzt bearbeitet 07.07.2026 19:09:30
pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating config dependency symlinks under node_modules/.pnpm-config. A malicious re...
CVE-2026-59196
- EPSS 0.29%
- Veröffentlicht 06.07.2026 15:18:53
- Zuletzt bearbeitet 07.07.2026 19:09:15
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Traversal aliases could escape that directory, while reserved aliases such as .bin or .pnpm could overwr...
CVE-2026-59194
- EPSS 0.29%
- Veröffentlicht 06.07.2026 15:16:28
- Zuletzt bearbeitet 07.07.2026 19:08:57
pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This vulnerability is fixed in 10.34.4 and 11.7.0.
CVE-2026-55180
- EPSS 0.33%
- Veröffentlicht 25.06.2026 17:00:35
- Zuletzt bearbeitet 29.06.2026 21:16:13
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository co...
CVE-2026-48995
- EPSS 0.16%
- Veröffentlicht 25.06.2026 16:58:57
- Zuletzt bearbeitet 29.06.2026 20:30:18
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from http...
CVE-2026-50017
- EPSS 0.38%
- Veröffentlicht 25.06.2026 16:56:04
- Zuletzt bearbeitet 30.06.2026 19:04:10
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. In the reproduced case, the user's npm config contains a default registry...
CVE-2026-50016
- EPSS 0.47%
- Veröffentlicht 25.06.2026 16:53:16
- Zuletzt bearbeitet 29.06.2026 23:57:03
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependen...
CVE-2026-50015
- EPSS 0.37%
- Veröffentlicht 25.06.2026 16:52:01
- Zuletzt bearbeitet 29.06.2026 21:15:11
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull reque...
CVE-2026-50014
- EPSS 0.26%
- Veröffentlicht 25.06.2026 16:51:16
- Zuletzt bearbeitet 29.06.2026 21:14:58
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a ma...
CVE-2026-50573
- EPSS 0.16%
- Veröffentlicht 25.06.2026 16:50:21
- Zuletzt bearbeitet 29.06.2026 21:15:58
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. When a package is alr...