Pnpm
This hub aggregates every CVE we track for Pnpm, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
35
CVEs tracked
1
Critical
17
High
0
In CISA KEV
Severity distribution
HIGH17MEDIUM12CRITICAL1
Monthly trend
0
0
1
0
0
0
1
0
0
0
0
0
0
0
0
8
0
0
0
0
16
3
2
2
2024-102026-09
Latest CVEs
The 15 most recently published vulnerabilities affecting Pnpm.
- GHSA-vx52-2968-3vc6pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml
- GHSA-2rx9-3g3h-c2jvpnpm: pacquet trust-lockfile install can create dependency symlinks outside the project
- CVE-2026-82393pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install7.5
- CVE-2026-82392pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph7.1
- CVE-2026-59195pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config8.2
- CVE-2026-59196pnpm: hoisted install imports lockfile alias outside node_modules7.1
- CVE-2026-59194pnpm: patch-remove could delete project-selected files outside the patches directory7.1
- GHSA-qrv3-253h-g69cpnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
- GHSA-72r4-9c5j-mj57pnpm: `patch-remove` could delete project-selected files outside the patches directory
- GHSA-fr4h-3cph-29xvpnpm: Hoisted install imports lockfile alias outside node_modules
- CVE-2026-55180pnpm: Repository config can expand victim environment secrets into registry requests before scripts run6.5
- CVE-2026-48995pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile7.5
- CVE-2026-50017pnpm binds unscoped user-level npm auth credentials to a repository-selected registry6.5
- CVE-2026-50016pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement8.8
- CVE-2026-50015pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)7.3
Product normalization is registry-driven with AI assist and human review. How it works