pnpm
4 known vulnerabilities in pnpm, with patch priority, exploit likelihood and the news covering them.
Latest vulnerabilities
- CVE-2026-101044 CVSS 7.1 high pacquet, the Rust package-manager component shipped in the pnpm npm package versions >=12.0.0-alpha.0 and <12.0.0-alpha.5, does not…
- CVE-2026-101043 CVSS 8.3 high pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy…
- CVE-2026-82393 CVSS 7.5 high pnpm is a package manager. Prior to 10.34.5 and 11.11.0, pnpm accepts a scoped path traversal in a tarball dependency's package.json…
- CVE-2026-82392 CVSS 7.1 high pnpm is a package manager. Prior to 10.34.5 and from 11.0.0 until 11.11.0, pnpm parses the package name from attacker-controlled…