Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

pnpm — Vulnerabilities & Security Advisories 27

All 27 CVE vulnerabilities found in pnpm, with AI-generated Chinese analysis, references, and POCs.

This page aggregates Common Weakness Enumerations associated with the package manager pnpm, categorized under the vendor ecosystem for node.js development tools. It collects data on security vulnerabilities affecting pnpm versions, spanning from initial releases through recent updates, covering issues related to dependency resolution, path traversal, and remote code execution risks. Readers can utilize this resource to track official advisories from the pnpm team, understand the prevalence and impact of specific weakness classes within this utility, and examine the chronological history of reported security flaws in the product. The content is curated to provide a clear view of how vulnerabilities have been addressed over time, helping developers assess risk when upgrading or maintaining their local development environments. By consolidating these findings, the page aims to support informed decision-making regarding version control and patch management for projects relying on pnpm. It serves as a reference point for security researchers and system administrators seeking to identify potential exposure vectors without needing to search multiple sources. The information presented is based on publicly available vulnerability databases and vendor notifications, ensuring accuracy and relevance for ongoing maintenance tasks. Users interested in the broader context of JavaScript package manager security may find this aggregation useful for comparative analysis against other tools in the same category.

Vendor: pnpm

CVE IDTitleCVSSSeverityPublished
CVE-2026-59195 pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config CWE-22 8.2 High2026-07-06
CVE-2026-59196 pnpm: hoisted install imports lockfile alias outside node_modules CWE-22 7.1 High2026-07-06
CVE-2026-59194 pnpm: patch-remove could delete project-selected files outside the patches directory CWE-22 7.1 High2026-07-06
CVE-2026-55180 pnpm: Repository config can expand victim environment secrets into registry requests before scripts run CWE-200 6.5 Medium2026-06-25
CVE-2026-48995 pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile CWE-353--2026-06-25
CVE-2026-50017 pnpm binds unscoped user-level npm auth credentials to a repository-selected registry CWE-200--2026-06-25
CVE-2026-50016 pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement CWE-23 8.8 High2026-06-25
CVE-2026-50015 pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) CWE-22 7.3 High2026-06-25
CVE-2026-50014 pnpm: Git Fetch Argument Injection via Lockfile resolution.commit CWE-88 6.4 Medium2026-06-25
CVE-2026-50573 pnpm: Unsafe default behavior breaks integrity check CWE-345 6.8 Medium2026-06-25
CVE-2026-50021 pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field CWE-354 6.8 Medium2026-06-25
CVE-2026-55700 pnpm: stage download writes outside destination via manifest version traversal CWE-22 7.1 High2026-06-25
CVE-2026-55699 pnpm: reserved bin name deletes PNPM_HOME during global remove CWE-22 6.5 Medium2026-06-25
CVE-2026-55698 pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes CWE-345 8.8 High2026-06-25
CVE-2026-55697 pnpm: Repository-controlled configDependencies can select a pacquet native install engine CWE-78 7.5 High2026-06-25
CVE-2026-55487 pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle CWE-346 7.5 High2026-06-25
CVE-2026-24131 pnpm has Path Traversal via arbitrary file permission modification CWE-22 7.7AIHighAI2026-01-26
CVE-2026-24056 pnpm has symlink traversal in file:/git dependencies CWE-22 7.7AIHighAI2026-01-26
CVE-2026-23890 pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin CWE-23 6.5 Medium2026-01-26
CVE-2026-23889 pnpm has Windows-specific tarball Path Traversal CWE-22 6.5 Medium2026-01-26
CVE-2026-23888 pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip) CWE-22 6.5 Medium2026-01-26
CVE-2025-69262 pnpm vulnerable to Command Injection via environment variable substitution CWE-78 7.6 High2026-01-07
CVE-2025-69264 pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default" CWE-693 8.8 High2026-01-07
CVE-2025-69263 pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies CWE-494 7.5 High2026-01-07
CVE-2024-47829 pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting CWE-328 6.5 Medium2025-04-23
CVE-2024-53866 pnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasion CWE-426 9.8 -2024-12-10
CVE-2023-37478 pnpm incorrectly parses tar archives relative to specification CWE-284 7.5 High2023-08-01

All 27 known CVE vulnerabilities affecting pnpm with full Chinese analysis, references, and POCs where available.