pnpm
OSS Librariesoss-project
Top products
Latest CVEs
The 15 most recently published vulnerabilities affecting pnpm.
- CVE-2026-82393pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install7.5
- CVE-2026-82392pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph7.1
- CVE-2026-59195pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config8.2
- CVE-2026-59196pnpm: hoisted install imports lockfile alias outside node_modules7.1
- CVE-2026-59194pnpm: patch-remove could delete project-selected files outside the patches directory7.1
- CVE-2026-55180pnpm: Repository config can expand victim environment secrets into registry requests before scripts run6.5
- CVE-2026-48995pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile7.5
- CVE-2026-50017pnpm binds unscoped user-level npm auth credentials to a repository-selected registry6.5
- CVE-2026-50016pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement8.8
- CVE-2026-50015pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)7.3
- CVE-2026-50014pnpm: Git Fetch Argument Injection via Lockfile resolution.commit6.4
- CVE-2026-50573pnpm: Unsafe default behavior breaks integrity check6.8
- CVE-2026-50021pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field6.8
- CVE-2026-55700pnpm: stage download writes outside destination via manifest version traversal7.1
- CVE-2026-55699pnpm: reserved bin name deletes PNPM_HOME during global remove6.5