CVEs we hold for Pnpm
Records whose assigning authority named Pnpm as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-82393pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on installpnpm
CVE-2026-82392pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraphpnpm
CVE-2026-59195pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configpnpm
CVE-2026-59194pnpm: patch-remove could delete project-selected files outside the patches directorypnpm
CVE-2026-55698pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytespnpm
CVE-2026-55697pnpm: Repository-controlled configDependencies can select a pacquet native install enginepnpm
CVE-2026-55180pnpm: Repository config can expand victim environment secrets into registry requests before scripts runpnpm
CVE-2026-50017pnpm binds unscoped user-level npm auth credentials to a repository-selected registrypnpm
CVE-2026-50016pnpm: Transitive dependency alias path traversal allows project path override via symlink replacementpnpm
CVE-2026-23890pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.binpnpm
CVE-2026-23888pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)pnpm
CVE-2024-53866pnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasionpnpm
CVE-2024-47829pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwritingpnpm
29 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.