vciy

CVEs we hold for Pnpm

Records whose assigning authority named Pnpm as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-82393pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installpnpm
CVE-2026-82392pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraphpnpm
CVE-2026-59196pnpm: hoisted install imports lockfile alias outside node_modulespnpm
CVE-2026-59195pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configpnpm
CVE-2026-59194pnpm: patch-remove could delete project-selected files outside the patches directorypnpm
CVE-2026-55700pnpm: stage download writes outside destination via manifest version traversalpnpm
CVE-2026-55699pnpm: reserved bin name deletes PNPM_HOME during global removepnpm
CVE-2026-55698pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytespnpm
CVE-2026-55697pnpm: Repository-controlled configDependencies can select a pacquet native install enginepnpm
CVE-2026-55487pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecyclepnpm
CVE-2026-55180pnpm: Repository config can expand victim environment secrets into registry requests before scripts runpnpm
CVE-2026-50573pnpm: Unsafe default behavior breaks integrity checkpnpm
CVE-2026-50021pnpm: Integrity Check Bypass via Missing Lockfile Integrity Fieldpnpm
CVE-2026-50017pnpm binds unscoped user-level npm auth credentials to a repository-selected registrypnpm
CVE-2026-50016pnpm: Transitive dependency alias path traversal allows project path override via symlink replacementpnpm
CVE-2026-50015pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)pnpm
CVE-2026-50014pnpm: Git Fetch Argument Injection via Lockfile resolution.commitpnpm
CVE-2026-48995pnpm: Tarball hash of GitHub git dependencies is not stored in lockfilepnpm
CVE-2026-24131pnpm has Path Traversal via arbitrary file permission modificationpnpm
CVE-2026-24056pnpm has symlink traversal in file:/git dependenciespnpm
CVE-2026-23890pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.binpnpm
CVE-2026-23889pnpm has Windows-specific tarball Path Traversalpnpm
CVE-2026-23888pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)pnpm
CVE-2025-69264pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"pnpm
CVE-2025-69263pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependenciespnpm
CVE-2025-69262pnpm vulnerable to Command Injection via environment variable substitutionpnpm
CVE-2024-53866pnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasionpnpm
CVE-2024-47829pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwritingpnpm
CVE-2023-37478pnpm incorrectly parses tar archives relative to specificationpnpm

29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.