pnpm vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
GHSA-QRV3-253H-G69CHighpnpm: pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configGHSA-72R4-9C5J-MJ57Highpnpm: pnpm: `patch-remove` could delete project-selected files outside the patches directoryGHSA-FR4H-3CPH-29XVHighpnpm: pnpm: Hoisted install imports lockfile alias outside node_modulesCVE-2026-55700Highpnpm: pnpm: `stage download` writes outside its destination directory via manifest name/version traversalCVE-2026-55699Mediumpnpm: pnpm: Reserved bin name deletes PNPM_HOME during global removeCVE-2026-55698Highpnpm: pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesCVE-2026-55697Highpnpm: pnpm: Repository-controlled configDependencies can select a pacquet native install engineCVE-2026-55487Highpnpm: pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycleCVE-2026-55180Mediumpnpm: pnpm: Repository config can expand victim environment secrets into registry requests before scripts runCVE-2026-50015Highpnpm: pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)CVE-2026-50017Mediumpnpm: pnpm binds unscoped user-level npm auth credentials to a repository-selected registryCVE-2026-50016Highpnpm: pnpm: Transitive dependency alias path traversal allows project path override via symlink replacementCVE-2026-50014Mediumpnpm: pnpm: Git Fetch Argument Injection via Lockfile resolution.commitCVE-2026-50021Mediumpnpm: pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity FieldCVE-2026-50573Mediumpnpm: pnpm: Unsafe default behavior breaks integrity checkCVE-2026-48995Mediumpnpm: pnpm: Tarball hash of GitHub git dependencies is not stored in lockfileCVE-2026-24131Mediumpnpm: pnpm has Path Traversal via arbitrary file permission modification CVE-2026-23888Mediumpnpm: pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)CVE-2026-23889Mediumpnpm: pnpm has Windows-specific tarball Path TraversalCVE-2026-23890Mediumpnpm: pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.binCVE-2026-24056Mediumpnpm: pnpm has symlink traversal in file:/git dependenciesCVE-2025-69264Highpnpm: pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"CVE-2025-69263Highpnpm: pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic DependenciesCVE-2025-69262Highpnpm: pnpm vulnerable to Command Injection via environment variable substitutionCVE-2024-47829Mediumpnpm: pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting

Stop the waste.
Protect your environment with Kodem.