HIGH8.8CVE-2026-55698pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes from 0, < 10.34.2
HIGH8.8CVE-2026-50016pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement from 0, < 10.34.0
HIGH8.8CVE-2025-69264pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default" >= 10.0.0, < 10.26.0
HIGH8.8Untrusted Search Path in PNPM
from 0, < 6.15.1
HIGH8.2pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
from 0, < 10.34.4
HIGH7.5pnpm: Repository-controlled configDependencies can select a pacquet native install engine
from 0, < 11.5.3
HIGH7.5pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
from 0, < 10.34.2
HIGH7.5pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
from 0, < 10.26.0
HIGH7.5pnpm vulnerable to Command Injection via environment variable substitution
>= 6.25.0, < 10.27.0
HIGH7.5pnpm incorrectly parses tar archives relative to specification
from 0, < 7.33.4
HIGH7.3pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
from 0, < 10.34.0
HIGH7.1pnpm: `patch-remove` could delete project-selected files outside the patches directory
from 0, < 10.34.4
HIGH7.1pnpm: Hoisted install imports lockfile alias outside node_modules
from 0, < 10.34.4
HIGH7.1pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
>= 11.3.0, < 11.5.3
MEDIUM6.8pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
>= 11.0.0, < 11.4.0
MEDIUM6.8pnpm: Unsafe default behavior breaks integrity check
from 0, < 10.34.0
MEDIUM6.5pnpm: Reserved bin name deletes PNPM_HOME during global remove
from 0, < 10.34.2
MEDIUM6.5pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
from 0, < 10.34.2
MEDIUM6.5pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
from 0, < 10.28.1
MEDIUM6.5pnpm has Windows-specific tarball Path Traversal
from 0, < 10.28.1
MEDIUM6.5pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
from 0, < 10.28.1
MEDIUM6.5pnpm has symlink traversal in file:/git dependencies
from 0, < 10.28.2
MEDIUM6.5pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
from 0, < 10.0.0
MEDIUM6.4pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
from 0, < 10.34.0
—pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
from 0, < 10.34.0
—pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
from 0, < 10.33.4
—pnpm has Path Traversal via arbitrary file permission modification
from 0, < 10.28.2
—pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion
from 0, < 9.15.0