CVE-2026-59196 is a HIGH severity vulnerability in pnpm, a package manager, with a CVSS score of 7.1. Prior to versions 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory, allowing traversal aliases to escape that directory and reserved aliases to overwrite pnpm-owned layout. This vulnerability has a significant impact on the security of systems us [truncated]
CVE-2026-59194 is a vulnerability in pnpm, a package manager, where a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This issue is fixed in pnpm versions 10.34.4 and 11.7.0. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. Users of pnpm package manager, especially those using versions p [truncated]
CVE-2026-50573 is a vulnerability in pnpm, a package manager used for Node.js projects. The issue arises during the installation of packages in non-frozen mode. Prior to versions 10.34.0 and 11.4.0, pnpm's install process can accept new remote package content even after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. This occurs when a package is already lock [truncated]
The CVE-2026-50017 vulnerability affects the pnpm package manager, allowing it to send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. This issue was fixed in versions 10.34.0 and 11.4.0. Users of pnpm should update to one of these versions to mitigate the vulnerability. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severit [truncated]
CVE-2025-69262 is a high-severity Command Injection vulnerability in pnpm, a package manager for Node.js. Versions 6.25.0 through 10.26.2 are affected. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. The issue is fixed in version 10.27.0. Defenders should prioritize patching due to the high CVSS score of 7.5 and the [truncated]
CVE-2025-69263 is a high-severity vulnerability affecting pnpm, a package manager for Node.js. Versions 10.26.2 and below store HTTP tarball dependencies and git-hosted tarballs in the lockfile without integrity hashes. This oversight allows remote servers to serve different content on each install, even when a lockfile is committed. An attacker can exploit this by publishing a package with an HTTP tarbal [truncated]