CVE-2025-69264

Source
https://cve.org/CVERecord?id=CVE-2025-69264
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69264.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2025-69264
Aliases
Downstream
Published
2026-01-07T21:53:09.806Z
Modified
2026-01-14T06:43:51.547100Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
Details

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDependencies mechanism, git dependencies can still execute prepare, prepublish, and prepack scripts during the fetch phase, enabling remote code execution without user consent or approval. This issue is fixed in version 10.26.0.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/69xxx/CVE-2025-69264.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-693"
    ]
}
References

Affected packages

Git / github.com/pnpm/pnpm

Affected ranges

Type
GIT
Repo
https://github.com/pnpm/pnpm
Events

Affected versions

Other

v1

v10.*

v10.0.0
v10.1.0
v10.10.0
v10.11.0
v10.12.1
v10.12.2
v10.12.3
v10.12.4
v10.13.0
v10.13.1
v10.14.0
v10.14.0-0
v10.15.0
v10.15.1
v10.16.0
v10.16.1
v10.17.0
v10.17.1
v10.18.0
v10.18.1
v10.18.2
v10.18.3
v10.19.0
v10.19.1-oidc-test.0
v10.19.1-oidc-test.1
v10.19.1-oidc-test.2
v10.19.1-oidc-test.3
v10.2.0
v10.2.1
v10.20.0
v10.21.0
v10.22.0
v10.23.0
v10.24.0
v10.25.0
v10.3.0
v10.4.0
v10.4.1
v10.5.0
v10.5.1
v10.5.2
v10.6.0
v10.6.1
v10.6.2
v10.6.3
v10.6.4
v10.6.5
v10.7.0
v10.8.0
v10.8.1
v10.9.0

Database specific

source

"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-69264.json"