Product
pnpm
12 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-24131
CVE-2026-24056
CVE-2026-23890
CVE-2026-23889
CVE-2026-23888
CVE-2025-69262
CVE-2025-69264
CVE-2025-69263
CVE-2024-47829
CVE-2024-53866
CVE-2023-37478
CVE-2022-26183
< 10.28.2
pnpm is a package manager. Prior to version 10.28.2, when pnpm processes a package's
directories.bin field, it uses `path.join()< 10.28.2
pnpm is a package manager. Prior to version 10.28.2, when pnpm installs a
file: (directory) or git: dependency, it follows sym< 10.28.1
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's bin linking allows malicious npm pac
< 10.28.1
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's tarball extraction allows malicious
< 10.28.1
pnpm is a package manager. Prior to version 10.28.1, a path traversal vulnerability in pnpm's binary fetcher allows malicious pack
>= 6.25.0 and < 10.27.0
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable
>= 10.0.0 and < 10.26.0
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm insta
< 10.26.0
pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile wi
< 10.0.0
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compre
< 9.15.0
The package manager pnpm prior to version 9.15.0 seems to mishandle overrides and global cache: Overrides from one workspace leak
< 7.33.4
pnpm is a package manager. It is possible to construct a tarball that, when installed via npm or parsed by the registry is safe, b
< 6.15.1
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected way