Pnpm

Pnpm

28 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.4%
  • Veröffentlicht 26.01.2026 21:37:17
  • Zuletzt bearbeitet 28.01.2026 17:47:32

pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files outside the intended extraction directory. The vulnerability has two attack vectors: (1) Malicious Z...

Exploit
  • EPSS 0.97%
  • Veröffentlicht 07.01.2026 22:30:07
  • Zuletzt bearbeitet 22.06.2026 14:39:11

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables ...

Exploit
  • EPSS 1.04%
  • Veröffentlicht 07.01.2026 21:53:09
  • Zuletzt bearbeitet 15.07.2026 02:17:51

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 ...

Exploit
  • EPSS 0.42%
  • Veröffentlicht 07.01.2026 21:31:07
  • Zuletzt bearbeitet 15.07.2026 02:17:51

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile i...

Exploit
  • EPSS 0.22%
  • Veröffentlicht 23.04.2025 15:42:12
  • Zuletzt bearbeitet 22.06.2026 14:39:30

pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although...

Exploit
  • EPSS 0.95%
  • Veröffentlicht 10.12.2024 18:15:42
  • Zuletzt bearbeitet 22.06.2026 14:38:57

The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata saved in global cache; npm metadata from global cache affects other workspaces; and installs by defaul...

  • EPSS 1.21%
  • Veröffentlicht 01.08.2023 12:15:09
  • Zuletzt bearbeitet 21.11.2024 08:11:47

pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed via pnpm is malicious, due to how pnpm parses tar archives. This can result in a package that appears ...

Exploit
  • EPSS 1.59%
  • Veröffentlicht 21.03.2022 22:15:07
  • Zuletzt bearbeitet 21.11.2024 06:53:33

PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execute PNPM commands in a directory containing malicious content. This vulnerability occurs when the appli...