Vulnerability index

Browse CVEs

28 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2026-59195 pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those na… Pnpm 10.34.4 / 11.8.0+ Fix from $1,9502026-07-06 HIGH 7.1 CVE-2026-59194 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted patch entry could resolve outside the configured patches directory and cause pnpm p… Pnpm 10.34.4 / 11.7.0+ Fix from $1,9502026-07-06 HIGH 7.1 CVE-2026-59196 pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory. Tra… Pnpm 10.34.4 / 11.7.0+ Fix from $1,9502026-07-06 HIGH 7.1 CVE-2026-55700 pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version… Pnpm 11.5.3+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-55487 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, f… Pnpm 10.34.2 / 11.5.3+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-55697 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. … Pnpm 10.34.2 / 11.5.3+ Fix from $1,9502026-06-25 HIGH 8.8 CVE-2026-55698 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.y… Pnpm 10.34.2 / 11.5.3+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-55180 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-… Pnpm 10.34.2 / 11.5.3+ Fix from $1,6002026-06-25 MEDIUM 6.5 CVE-2026-55699 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, Manifest bin object keys such as "", ".", and ".." passed pnpm's bin-name guard. When a malic… Pnpm 10.34.2 / 11.5.3+ Fix from $1,6002026-06-25 HIGH 8.8 CVE-2026-50016 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path trav… Pnpm 10.34.0 / 11.4.0+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-50021 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is abs… Pnpm 10.34.0 / 11.4.0+ Fix from $1,9502026-06-25 HIGH 8.1 CVE-2026-50573 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that … Pnpm 10.34.0 / 11.4.0+ Fix from $1,9502026-06-25 HIGH 7.3 CVE-2026-50014 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- sep… Pnpm 10.34.0 / 11.4.0+ Fix from $1,9502026-06-25 HIGH 7.3 CVE-2026-50015 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file p… Pnpm 10.34.0 / 11.4.0+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-50017 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm can send user-level unscoped npm authentication credentials to a registry chosen by a re… Pnpm 10.34.0 / 11.4.0+ Fix from $1,6002026-06-25 HIGH 7.5 CVE-2026-48995 pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will inst… Pnpm 10.33.4 / 11.0.7+ Fix from $1,9502026-06-25 MEDIUM 6.5 CVE-2026-23888 pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious packages to write files… Pnpm 10.28.1+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-23889 pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious packages to write f… Pnpm 10.28.1+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-23890 pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm packages to create exe… Pnpm 10.28.1+ Fix from $1,6002026-01-26 MEDIUM 6.5 CVE-2026-24056 pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a `file:` (directory) or `git:` dependency, it follows symlinks and reads the… Pnpm 10.28.2+ Fix from $1,6002026-01-26 MEDIUM 5.5 CVE-2026-24131 pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's `directories.bin` field, it uses `path.join()` without validatin… Pnpm 10.28.2+ Fix from $1,6002026-01-26 HIGH 7.8 CVE-2025-69262 pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .np… Pnpm 10.27.0+ Fix from $1,9502026-01-07 CRITICAL 9.8 CVE-2025-69264 pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing t… Pnpm 10.26.0+ Fix from $2,3002026-01-07 HIGH 8.8 CVE-2025-69263 pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity has… Pnpm 10.26.0+ Fix from $1,9502026-01-07 MEDIUM 6.5 CVE-2024-47829 pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and… Pnpm 10.0.0+ Fix from $1,6002025-04-23 CRITICAL 9.8 CVE-2024-53866 The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak into npm metadata s… Pnpm 9.15.0+ Fix from $2,3002024-12-10 CRITICAL 9.8 CVE-2023-37478 pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, but when installed v… Pnpm 7.33.4 / 8.6.8+ Fix from $2,3002023-08-01 HIGH 8.8 CVE-2022-26183 PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when users execut… Pnpm 6.15.1+ Fix from $1,9502022-03-21