All 27 CVE vulnerabilities found in pnpm, with AI-generated Chinese analysis, references, and POCs.
This page aggregates Common Weakness Enumerations associated with the package manager pnpm, categorized under the vendor ecosystem for node.js development tools. It collects data on security vulnerabilities affecting pnpm versions, spanning from initial releases through recent updates, covering issues related to dependency resolution, path traversal, and remote code execution risks. Readers can utilize this resource to track official advisories from the pnpm team, understand the prevalence and impact of specific weakness classes within this utility, and examine the chronological history of reported security flaws in the product. The content is curated to provide a clear view of how vulnerabilities have been addressed over time, helping developers assess risk when upgrading or maintaining their local development environments. By consolidating these findings, the page aims to support informed decision-making regarding version control and patch management for projects relying on pnpm. It serves as a reference point for security researchers and system administrators seeking to identify potential exposure vectors without needing to search multiple sources. The information presented is based on publicly available vulnerability databases and vendor notifications, ensuring accuracy and relevance for ongoing maintenance tasks. Users interested in the broader context of JavaScript package manager security may find this aggregation useful for comparative analysis against other tools in the same category.
Vendor: pnpm
All 27 known CVE vulnerabilities affecting pnpm with full Chinese analysis, references, and POCs where available.