Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

Security Intel Hub 19+

Curated security advisories, vulnerability analyses, and exploit write-ups — auto-cleaned and translated to English. Updated continuously.

Examples: RCE · SSRF · GHSA · log4j
Filter
Clear filters
High
pnpm Vulnerability: Hoisted Install Imports Lockfile Alias Outside node_modules
CAND-PNPM-059 · github.com · 2026-07-07
pnpm <10.34.4 · pnpm >=11.0.0 <11.7.0
Read more
Premium intel
High
pnpm Path Traversal in configDependencies allows Symlink Creation
GHSA-pnpm-path-traversal · github.com · 2026-07-07
pnpm <10.34.4 · pnpm >=11.0.0 <11.8.0
Read more
High
pnpm/npm Environment Key Leakage via .npmrc Expansion (CAND-PNPM-122)
GHSA-batch-2026-06-09 · github.com · 2026-06-27
pnpm < 10.34.2 · npm < 11.0.0 …
Read more
High
CVE-2025-55699 PNPM Global Remove Directory Traversal Vulnerability
CAND-PNPM-085 · github.com · 2026-06-27
pnpm <10.34.2 · pnpm >=11.0.0 <11.5.3
Read more
High
pnpm Dependency Source Identifier Normalization Bypass (CVE-2025-53487)
CVE-2025-53487 · github.com · 2026-06-27
pnpm <10.34.2 · pnpm >=11.0.0 <11.5.3
Read more
High
pnpm Unscoped Auth Credential Leakage (CVE-2024-50017)
CVE-2024-50017 · github.com · 2026-06-27
pnpm <10.34.0 · pnpm >=11.0.0 <11.4.0
Read more
Unknown
pnpm Integrity Check Bypass Vulnerability (CVE-2025-5073)
CVE-2025-5073 · github.com · 2026-06-27
pnpm <10.34.0 · pnpm >=11.0.0 <11.4.0
Read more
Premium intel
High
pnpm Repository-controlled configDependencies Native Install Engine RCE Vulnerability
CVE-2026-55697 · github.com · 2026-06-27
pnpm <10.34.2 · pnpm >=11.0.0 <11.5.3
Read more
Medium
CVE-2024-4995: pnpm git dependency tarball hash not stored in lockfile
CVE-2024-4995 · github.com · 2026-06-27
pnpm <10.3.4 · pnpm >=11.0.0 <11.0.7
Read more
Premium intel
High
pnpm transitive dependency alias path traversal via symlink replacement
github.com · 2026-06-27
pnpm <10.34.0 · pnpm >=11.0.0 <11.4.0
Read more
High
pnpm RCE via Git Fetch Argument Injection (CVE-2024-50214) with PoC
CVE-2024-50214 · github.com · 2026-06-27
pnpm < 10.34.0 · pnpm >= 11.0.0 < 11.4.0
Read more
High
pnpm Integrity Check Bypass in Tarball Extraction via Missing Lockfile Field
github.com · 2026-06-27
pnpm <10.3.1 · pnpm >=11.0.0 <11.4.0
Read more
Critical
pnpm path traversal in patch application allows arbitrary file write/deletion
github.com · 2026-06-27
pnpm <10.34.0 · pnpm >=11.0.0 <11.4.0
Read more
Premium intel
High
pnpm Lockfile Injection Leading to Code Execution (CAND-PNPM-063)
GHSA-jhc-m6cf-6jmbjybl · github.com · 2026-06-27
pnpm · @pnpm/installing.env-installer
Read more
High
pnpm 'stage download' Path Traversal via Manifest Version Traversal (CVE-2024-55700)
CVE-2024-55700 · github.com · 2026-06-27
pnpm >=11.3.0 <11.5.3
Read more
Premium intel
High
pnpm <=10.28.0 Path Traversal Vulnerability (CWE-22)
github.com · 2026-01-27
pnpm <= 10.28.0
Read more
Medium
pnpm bin path traversal vulnerability (CVE-2026-23890) with PoC
GHSA-xpqm-wm3m-f34h · github.com · 2026-01-27
pnpm <= 10.28.0
Read more

All articles are auto-cleaned (markdown extraction + LLM noise removal) and translated to English by our offline pipeline. Source URL is always preserved at the bottom of each article.

Want a specific source covered? Email us — we add new feeds weekly.