Pnpm

Pnpm

32 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.47%
  • Veröffentlicht 25.06.2026 16:53:16
  • Zuletzt bearbeitet 29.06.2026 23:57:03

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, pnpm later uses that alias as a filesystem path when linking dependen...

Exploit
  • EPSS 0.37%
  • Veröffentlicht 25.06.2026 16:52:01
  • Zuletzt bearbeitet 29.06.2026 21:15:11

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch files. An attacker who contributes a malicious patch file via a pull reque...

Exploit
  • EPSS 0.26%
  • Veröffentlicht 25.06.2026 16:51:16
  • Zuletzt bearbeitet 29.06.2026 21:14:58

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a ma...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 25.06.2026 16:50:21
  • Zuletzt bearbeitet 29.06.2026 21:15:58

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. When a package is alr...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 25.06.2026 16:48:27
  • Zuletzt bearbeitet 29.06.2026 21:15:33

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolution. If an attacker can both modify pnpm-lock.yaml to remove the integri...

Exploit
  • EPSS 0.35%
  • Veröffentlicht 25.06.2026 16:47:21
  • Zuletzt bearbeitet 29.06.2026 21:16:55

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite another reacha...

Exploit
  • EPSS 0.41%
  • Veröffentlicht 25.06.2026 16:44:32
  • Zuletzt bearbeitet 29.06.2026 21:16:36

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malicious package was installed globally, later global remove, update, or add-replacement flows could re-d...

Exploit
  • EPSS 0.27%
  • Veröffentlicht 25.06.2026 16:43:47
  • Zuletzt bearbeitet 30.06.2026 19:03:56

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies e...

Exploit
  • EPSS 0.17%
  • Veröffentlicht 25.06.2026 16:42:08
  • Zuletzt bearbeitet 30.06.2026 19:04:04

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependency and pnpm...

Exploit
  • EPSS 0.16%
  • Veröffentlicht 25.06.2026 16:41:12
  • Zuletzt bearbeitet 29.06.2026 21:16:26

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different ...