CVE-2026-55698
- EPSS -
- Veröffentlicht 25.06.2026 16:43:47
- Zuletzt bearbeitet 26.06.2026 05:16:30
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies e...
CVE-2026-55697
- EPSS -
- Veröffentlicht 25.06.2026 16:42:08
- Zuletzt bearbeitet 26.06.2026 05:16:30
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependency and pnpm...
CVE-2026-55487
- EPSS -
- Veröffentlicht 25.06.2026 16:41:12
- Zuletzt bearbeitet 25.06.2026 19:16:42
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different ...
CVE-2026-24131
- EPSS 0.24%
- Veröffentlicht 26.01.2026 22:03:33
- Zuletzt bearbeitet 28.01.2026 17:05:46
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validating the result stays within the package root. A malicious npm package can specify `"directories": {"bin...
CVE-2026-24056
- EPSS 0.47%
- Veröffentlicht 26.01.2026 21:59:32
- Zuletzt bearbeitet 28.01.2026 17:27:13
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads their target contents without constraining them to the package root. A malicious package containing a sy...
CVE-2026-23890
- EPSS 0.44%
- Veröffentlicht 26.01.2026 21:53:40
- Zuletzt bearbeitet 28.01.2026 17:32:21
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create executable shims or symlinks outside of `node_modules/.bin`. Bin names starting with `@` bypass validati...
CVE-2026-23889
- EPSS 0.43%
- Veröffentlicht 26.01.2026 21:50:55
- Zuletzt bearbeitet 28.01.2026 17:33:40
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write files outside the package directory on Windows. The path normalization only checks for `./` but not `....
CVE-2026-23888
- EPSS 0.4%
- Veröffentlicht 26.01.2026 21:37:17
- Zuletzt bearbeitet 28.01.2026 17:47:32
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious Z...
CVE-2025-69262
- EPSS 0.95%
- Veröffentlicht 07.01.2026 22:30:07
- Zuletzt bearbeitet 22.06.2026 14:39:11
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables ...
CVE-2025-69264
- EPSS 0.81%
- Veröffentlicht 07.01.2026 21:53:09
- Zuletzt bearbeitet 12.01.2026 21:53:20
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 ...