Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
GHSA-c59q-g84q-2gj5
  • npm/pnpm
pnpm: Virtual store linker path traversal via unvalidated depPath name in lockfileToDepGraph 02 Sep
  • Fix available
  • Severity - 7.1 (High)
GHSA-vq4v-j7r6-jq4m
  • npm/pnpm
pnpm: A tarball dependency's manifest `name` escapes node_modules → arbitrary file write/overwrite on install 02 Sep
  • Fix available
  • Severity - 7.5 (High)
GHSA-vx52-2968-3vc6
  • npm/pnpm
pnpm: Environment secrets exfiltrated via env-placeholder expansion in proxy settings read from an untrusted pnpm-workspace.yaml 01 Sep
  • Fix available
  • Severity - 7.4 (High)
GHSA-2rx9-3g3h-c2jv
  • npm/pnpm
pnpm: pacquet trust-lockfile install can create dependency symlinks outside the project 01 Sep
  • Fix available
  • Severity - 7.1 (High)
MAL-2026-11621
  • npm/@onereach/pnpm-audit-junit
Malicious code in @onereach/pnpm-audit-junit (npm) 04 Aug
  • No fix available
MAL-2026-6716
  • npm/test-pkg-pnpm
Malicious code in test-pkg-pnpm (npm) 01 Jul
  • No fix available
GHSA-qrv3-253h-g69c
  • npm/pnpm
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config 27 Jun
  • Fix available
  • Severity - 8.2 (High)
GHSA-72r4-9c5j-mj57
  • npm/pnpm
pnpm: `patch-remove` could delete project-selected files outside the patches directory 27 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-fr4h-3cph-29xv
  • npm/pnpm
pnpm: Hoisted install imports lockfile alias outside node_modules 27 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-v23m-ccfg-pq9h
  • npm/pnpm
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal 26 Jun
  • Fix available
  • Severity - 7.1 (High)
GHSA-4gxm-v5v7-fqc4
  • npm/pnpm
pnpm: Reserved bin name deletes PNPM_HOME during global remove 26 Jun
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-w466-c33r-3gjp
  • npm/pnpm
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes 26 Jun
  • Fix available
  • Severity - 8.8 (High)
GHSA-gj8w-mvpf-x27x
  • npm/pnpm
pnpm: Repository-controlled configDependencies can select a pacquet native install engine 26 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-5wx6-mg75-v57r
  • npm/pnpm
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle 26 Jun
  • Fix available
  • Severity - 7.5 (High)
GHSA-3qhv-2rgh-x77r
  • npm/pnpm
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run 26 Jun
  • Fix available
  • Severity - 6.5 (Medium)
GHSA-rxhj-4m44-96r4
  • npm/pnpm
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal) 26 Jun
  • Fix available
  • Severity - 7.3 (High)