📦 Pnpm

by Pnpm

🔍 What is Pnpm?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-53866

CRITICAL CVSS 9.8 Dec 10, 2024

This vulnerability in pnpm package manager allows malicious npm packages to bypass security controls and execute arbitrary code during installation. It affects all users running pnpm versions before 9...

CVE-2025-69262

HIGH CVSS 7.5 Jan 7, 2026

This CVE describes a command injection vulnerability in pnpm package manager versions 6.25.0 through 10.26.2. Attackers who can control environment variables during pnpm operations can achieve remote ...

CVE-2025-69263

HIGH CVSS 7.5 Jan 7, 2026

This CVE allows attackers to serve malicious code through HTTP tarball dependencies in pnpm packages. The lockfile fails to provide integrity verification, enabling different content to be delivered o...

CVE-2025-69264

HIGH CVSS 8.8 Jan 7, 2026

This vulnerability in pnpm package manager versions 10.0.0 through 10.25 allows git-hosted dependencies to execute arbitrary code during installation. It bypasses pnpm v10's security feature that disa...

CVE-2023-37478

HIGH CVSS 7.5 Aug 1, 2023

This vulnerability in pnpm allows attackers to create specially crafted tarballs that appear safe when inspected on npm registry or installed via npm, but execute malicious code when installed via pnp...

CVE-2024-47829

MEDIUM CVSS 6.5 Apr 23, 2025

This vulnerability in pnpm (package manager) uses MD5 hashing for path shortening, which can cause collisions where two different libraries get stored in the same directory path. This affects develope...