pkg:npm/pnpm
12 total CVEsHIGH5MEDIUM5
✅ Check your installed version
All known vulnerabilities
- >= 10.0.0, < 10.26.0
- from 0, < 6.15.1
- from 0, < 10.26.0
- >= 6.25.0, < 10.27.0
- from 0, < 7.33.4
- MEDIUM6.5CVE-2026-23888pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)from 0, < 10.28.1
- from 0, < 10.28.1
- MEDIUM6.5CVE-2026-23890pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.binfrom 0, < 10.28.1
- from 0, < 10.28.2
- MEDIUM6.5CVE-2024-47829pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwritingfrom 0, < 10.0.0
- from 0, < 10.28.2
- from 0, < 9.15.0