PatchSiren

pnpm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH pnpm CVE published 2026-07-06

CVE-2026-59196

CVE-2026-59196 is a HIGH severity vulnerability in pnpm, a package manager, with a CVSS score of 7.1. Prior to versions 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted node_modules directory, allowing traversal aliases to escape that directory and reserved aliases to overwrite pnpm-owned layout. This vulnerability has a significant impact on the security of systems us [truncated]

HIGH pnpm CVE published 2026-07-06

CVE-2026-59194

CVE-2026-59194 is a vulnerability in pnpm, a package manager, where a crafted patch entry could resolve outside the configured patches directory and cause pnpm patch-remove to delete an arbitrary reachable file. This issue is fixed in pnpm versions 10.34.4 and 11.7.0. The vulnerability has a CVSS score of 7.1 and is considered HIGH severity. Users of pnpm package manager, especially those using versions p [truncated]

MEDIUM pnpm CVE published 2026-06-25

CVE-2026-50573

CVE-2026-50573 is a vulnerability in pnpm, a package manager used for Node.js projects. The issue arises during the installation of packages in non-frozen mode. Prior to versions 10.34.0 and 11.4.0, pnpm's install process can accept new remote package content even after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. This occurs when a package is already lock [truncated]

MEDIUM pnpm CVE published 2026-06-25

CVE-2026-50017

The CVE-2026-50017 vulnerability affects the pnpm package manager, allowing it to send user-level unscoped npm authentication credentials to a registry chosen by a repository-local .npmrc file. This issue was fixed in versions 10.34.0 and 11.4.0. Users of pnpm should update to one of these versions to mitigate the vulnerability. The vulnerability has a CVSS score of 6.9 and is classified as MEDIUM severit [truncated]

HIGH pnpm CVE published 2026-01-07

CVE-2025-69262

CVE-2025-69262 is a high-severity Command Injection vulnerability in pnpm, a package manager for Node.js. Versions 6.25.0 through 10.26.2 are affected. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. The issue is fixed in version 10.27.0. Defenders should prioritize patching due to the high CVSS score of 7.5 and the [truncated]

HIGH pnpm CVE published 2026-01-07

CVE-2025-69263

CVE-2025-69263 is a high-severity vulnerability affecting pnpm, a package manager for Node.js. Versions 10.26.2 and below store HTTP tarball dependencies and git-hosted tarballs in the lockfile without integrity hashes. This oversight allows remote servers to serve different content on each install, even when a lockfile is committed. An attacker can exploit this by publishing a package with an HTTP tarbal [truncated]