Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pnpm — Vulnerabilities & Security Advisories 27

Browse all 27 CVE security advisories affecting pnpm. AI-powered Chinese analysis, POCs, and references for each vulnerability.

pnpm serves as a fast, disk-space-efficient package manager for JavaScript projects, addressing dependency management challenges. Historically, it has faced vulnerabilities including remote code execution through malicious packages, cross-site scripting flaws, and privilege escalation risks. The project maintains 11 CVEs on record, with notable incidents including RCE vulnerabilities in package resolution and extraction mechanisms. Security characteristics include a focus on deterministic builds and reduced attack surface compared to some alternatives, though its complex dependency resolution has introduced potential vectors for exploitation. Regular updates address these issues, but users should monitor advisories for newly discovered weaknesses in the package ecosystem.

Top products by pnpm: pnpm
HighCAND-PNPM-0592026-07-07
CAND-PNPM-059: hoisted install imports lockfile alias outside node_modules · Advisory · pnpm/pnpm · GitHub
HighGHSA-pnpm-path-traversal2026-07-07
Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config · Advisory ·
High2026-06-27
fix: validate staged tarball filenames by zkochan · Pull Request #12303 · pnpm/pnpm · GitHub
HighGHSA-batch-2026-06-092026-06-27
CAND-PNPM-122: Repository config can expand victim environment secrets into registry requests before scripts run · Advis
HighCAND-PNPM-0852026-06-27
CAND-PNPM-085: reserved bin name deletes PNPM_HOME during global remove · Advisory · pnpm/pnpm · GitHub
HighCVE-2024-500172026-06-27
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry · Advisory · pnpm/pnpm · GitHub
HighCVE-2025-534872026-06-27
CAND-PNPM-123: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle · Advisory · pnpm/pnpm · GitHub
UnknownCVE-2025-50732026-06-27
Unsafe default behavior breaks integrity check · Advisory · pnpm/pnpm · GitHub
HighCVE-2026-556972026-06-27
CAND-PNPM-097: Repository-controlled configDependencies can select a pacquet native install engine · Advisory · pnpm/pnp
High2026-06-27
Transitive dependency alias path traversal allows project path override via symlink replacement · Advisory · pnpm/pnpm ·
MediumCVE-2024-49952026-06-27
Tarball hash of GitHub git dependencies is not stored in lockfile · Advisory · pnpm/pnpm · GitHub
HighCVE-2024-502142026-06-27
Git Fetch Argument Injection via Lockfile resolution.commit · Advisory · pnpm/pnpm · GitHub
High2026-06-27
Integrity Check Bypass via Missing Lockfile Integrity Field · Advisory · pnpm/pnpm · GitHub
Critical2026-06-27
Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) · Advisory · pnpm/pnpm · GitHub
HighGHSA-jhc-m6cf-6jmbjybl2026-06-27
CAND-PNPM-063: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm byte
HighCVE-2024-557002026-06-27
CAND-PNPM-038: stage download writes outside destination via manifest version traversal · Advisory · pnpm/pnpm · GitHub
High2026-01-27
Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip) · Advisory · pnpm/pnpm · GitHub
MediumCVE-2026-241312026-01-27
Arbitrary file permission modification via directories.bin path traversal · Advisory · pnpm/pnpm · GitHub
MediumGHSA-xpqm-wm3m-f34h2026-01-27
Scoped bin name path traversal allows arbitrary file creation outside node_modules/.bin · Advisory · pnpm/pnpm · GitHub

Showing up to 20 recent security advisories. View all →

This page lists every published CVE security advisory associated with pnpm. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.