Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

pnpm — Vulnerabilities & Security Advisories 31

All 31 CVE vulnerabilities found in pnpm, with AI-generated Chinese analysis, references, and POCs.

This page aggregates vulnerability data for pnpm, the high-performance Node.js package manager maintained by the Zoltan Kochan team. It collects security disclosures affecting pnpm core, its registry clients, and associated lockfile parsing components, covering incidents reported from the tool’s initial public release through the most recent annual security audit cycles. Readers can use this resource to track vendor-specific advisories, understand recurring weakness classes such as prototype pollution or arbitrary code execution, and review the product’s historical vulnerability landscape. The dataset includes details on affected versions, remediation status, and links to official patch releases. It serves as a centralized reference for security engineers, supply chain auditors, and developers who rely on pnpm for dependency management. By examining the temporal distribution of flaws, users can identify periods of heightened activity or specific architectural changes that introduced new attack surfaces. The page does not contain proprietary exploit code or unverified third-party claims, focusing instead on confirmed issues acknowledged by the maintainers or disclosed through coordinated vulnerability reporting channels. This collection helps organizations assess risk exposure when integrating pnpm into their build pipelines or containerized environments. Updates are synchronized with major security bulletins, ensuring that critical patches and version constraints are clearly documented for compliance tracking.

Vendor: pnpm

CVE ID Title CVSS Severity Published
CVE-2023-37478 pnpm incorrectly parses tar archives relative to specification CWE-284 7.5 High 2023-08-01

All 31 known CVE vulnerabilities affecting pnpm with full Chinese analysis, references, and POCs where available.