Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pnpm — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in pnpm, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for pnpm, the high-performance Node.js package manager maintained by the Zoltan Kochan team. It collects security disclosures affecting pnpm core, its registry clients, and associated lockfile parsing components, covering incidents reported from the tool’s initial public release through the most recent annual security audit cycles. Readers can use this resource to track vendor-specific advisories, understand recurring weakness classes such as prototype pollution or arbitrary code execution, and review the product’s historical vulnerability landscape. The dataset includes details on affected versions, remediation status, and links to official patch releases. It serves as a centralized reference for security engineers, supply chain auditors, and developers who rely on pnpm for dependency management. By examining the temporal distribution of flaws, users can identify periods of heightened activity or specific architectural changes that introduced new attack surfaces. The page does not contain proprietary exploit code or unverified third-party claims, focusing instead on confirmed issues acknowledged by the maintainers or disclosed through coordinated vulnerability reporting channels. This collection helps organizations assess risk exposure when integrating pnpm into their build pipelines or containerized environments. Updates are synchronized with major security bulletins, ensuring that critical patches and version constraints are clearly documented for compliance tracking.

Vendor: pnpm

CVE ID Title CVSS Severity Published
CVE-2026-101044 pacquet before 12.0.0-alpha.5 Path Traversal via lockfile alias CWE-22 7.1 High 2026-09-27
CVE-2026-101043 pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings CWE-201 7.4 High 2026-09-27
CVE-2026-82393 pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install CWE-22 7.5 High 2026-08-31
CVE-2026-82392 pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph CWE-22 7.1 High 2026-08-31
CVE-2026-59195 pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config CWE-22 8.2 High 2026-07-06
CVE-2026-59196 pnpm: hoisted install imports lockfile alias outside node_modules CWE-22 7.1 High 2026-07-06
CVE-2026-59194 pnpm: patch-remove could delete project-selected files outside the patches directory CWE-22 7.1 High 2026-07-06
CVE-2026-55180 pnpm: Repository config can expand victim environment secrets into registry requests before scripts run CWE-200 6.5 Medium 2026-06-25
CVE-2026-48995 pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile CWE-353 - - 2026-06-25
CVE-2026-50017 pnpm binds unscoped user-level npm auth credentials to a repository-selected registry CWE-200 - - 2026-06-25
CVE-2026-50016 pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement CWE-23 8.8 High 2026-06-25
CVE-2026-50015 pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) CWE-22 7.3 High 2026-06-25
CVE-2026-50014 pnpm: Git Fetch Argument Injection via Lockfile resolution.commit CWE-88 6.4 Medium 2026-06-25
CVE-2026-50573 pnpm: Unsafe default behavior breaks integrity check CWE-345 6.8 Medium 2026-06-25
CVE-2026-50021 pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field CWE-354 6.8 Medium 2026-06-25
CVE-2026-55700 pnpm: stage download writes outside destination via manifest version traversal CWE-22 7.1 High 2026-06-25
CVE-2026-55699 pnpm: reserved bin name deletes PNPM_HOME during global remove CWE-22 6.5 Medium 2026-06-25
CVE-2026-55698 pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes CWE-345 8.8 High 2026-06-25
CVE-2026-55697 pnpm: Repository-controlled configDependencies can select a pacquet native install engine CWE-78 7.5 High 2026-06-25
CVE-2026-55487 pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle CWE-346 7.5 High 2026-06-25
CVE-2026-24131 pnpm has Path Traversal via arbitrary file permission modification CWE-22 7.7AI High AI 2026-01-26
CVE-2026-24056 pnpm has symlink traversal in file:/git dependencies CWE-22 7.7AI High AI 2026-01-26
CVE-2026-23890 pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin CWE-23 6.5 Medium 2026-01-26
CVE-2026-23889 pnpm has Windows-specific tarball Path Traversal CWE-22 6.5 Medium 2026-01-26
CVE-2026-23888 pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip) CWE-22 6.5 Medium 2026-01-26
CVE-2025-69262 pnpm vulnerable to Command Injection via environment variable substitution CWE-78 7.6 High 2026-01-07
CVE-2025-69264 pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default" CWE-693 8.8 High 2026-01-07
CVE-2025-69263 pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies CWE-494 7.5 High 2026-01-07
CVE-2024-47829 pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting CWE-328 6.5 Medium 2025-04-23
CVE-2024-53866 pnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasion CWE-426 9.8 - 2024-12-10

All 31 known CVE vulnerabilities affecting pnpm with full Chinese analysis, references, and POCs where available.