Pnpm is a package manager for JavaScript and Node.js ecosystems that occupies a prominent position in the developer toolchain, and vulnerabilities affecting it carry outsized risk due to the vendor's deep placement in build and dependency-resolution workflows. The exposure clusters around path-traversal, path-validation, and code-integrity issues alongside improper access control, reflecting the inherent trust and file-system privileges that package managers require; vulnerabilities in this class skew toward serious outcomes and can affect downstream projects transitioning or installing dependencies. Defenders should treat pnpm advisories with urgency, particularly those involving dependency handling or file-system operations, since remediation often requires coordinated updates across development environments; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Pnpm over time
Signals from CVEs in this vendor scope (28 CVEs).
28 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-50016HIGH pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install, | Jun 25, 2026 | 8.8 | 39 | NO | NO |
CVE-2026-55698HIGH pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct p | Jun 25, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-59195HIGH pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating conf | Jul 6, 2026 | 8.2 | 37 | NO | NO |
CVE-2026-55697HIGH pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository | Jun 25, 2026 | 8.8 | 37 | NO | NO |
CVE-2026-55487HIGH pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. | Jun 25, 2026 | 8.8 | 37 | NO | NO |
CVE-2025-69264CRITICAL pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Depend | Jan 7, 2026 | 9.8 | 37 | NO | NO |
CVE-2026-50573HIGH pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not | Jun 25, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-50021HIGH pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolutio | Jun 25, 2026 | 8.1 | 35 | NO | NO |
CVE-2026-50015HIGH pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch file | Jun 25, 2026 | 7.3 | 34 | NO | NO |
CVE-2026-50014HIGH pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validat | Jun 25, 2026 | 7.3 | 34 | NO | NO |
Signals from CVEs in this vendor scope (28 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Pnpm.
Media articles that mention a CVE ID that affects a product developed by Pnpm — matched by CVE ID, not by vendor name.