CVE-2025-69263
- EPSS 0.23%
- Veröffentlicht 07.01.2026 21:31:07
- Zuletzt bearbeitet 22.06.2026 14:38:42
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile i...
CVE-2024-47829
- EPSS 0.19%
- Veröffentlicht 23.04.2025 15:42:12
- Zuletzt bearbeitet 22.06.2026 14:39:30
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although...
CVE-2024-53866
- EPSS 0.95%
- Veröffentlicht 10.12.2024 18:15:42
- Zuletzt bearbeitet 22.06.2026 14:38:57
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by defaul...
CVE-2023-37478
- EPSS 0.93%
- Veröffentlicht 01.08.2023 12:15:09
- Zuletzt bearbeitet 21.11.2024 08:11:47
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears ...
CVE-2022-26183
- EPSS 1.57%
- Veröffentlicht 21.03.2022 22:15:07
- Zuletzt bearbeitet 21.11.2024 06:53:33
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the appli...