Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Pnpm

First CVE: Mar 21, 2022Active for: 4 yearsTotal CVEs: 28
42.6
VTI Score
High

Pnpm is a package manager for JavaScript and Node.js ecosystems that occupies a prominent position in the developer toolchain, and vulnerabilities affecting it carry outsized risk due to the vendor's deep placement in build and dependency-resolution workflows. The exposure clusters around path-traversal, path-validation, and code-integrity issues alongside improper access control, reflecting the inherent trust and file-system privileges that package managers require; vulnerabilities in this class skew toward serious outcomes and can affect downstream projects transitioning or installing dependencies. Defenders should treat pnpm advisories with urgency, particularly those involving dependency handling or file-system operations, since remediation often requires coordinated updates across development environments; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
28
Total CVEs
More Total CVEs than 97% of tracked vendors
5.6
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 98% of tracked vendors
7.7
Avg CVSS Score
Higher Avg CVSS Score than 73% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Pnpm over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 21, 2022
4 years ago
Most Recent CVE
Jul 6, 2026
18 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (28 CVEs).

28 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-50016HIGH
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm allows a transitive dependency alias from registry package metadata to contain path traversal segments. During install,
Jun 25, 20268.839NONO
CVE-2026-55698HIGH
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct p
Jun 25, 20268.838NONO
CVE-2026-59195HIGH
pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies section and uses those names directly when creating conf
Jul 6, 20268.237NONO
CVE-2026-55697HIGH
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository
Jun 25, 20268.837NONO
CVE-2026-55487HIGH
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators.
Jun 25, 20268.837NONO
CVE-2025-69264CRITICAL
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Depend
Jan 7, 20269.837NONO
CVE-2026-50573HIGH
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not
Jun 25, 20268.135NONO
CVE-2026-50021HIGH
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolutio
Jun 25, 20268.135NONO
CVE-2026-50015HIGH
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's patch application pipeline (@pnpm/patch-package) performs no path validation on file paths extracted from .patch file
Jun 25, 20267.334NONO
CVE-2026-50014HIGH
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validat
Jun 25, 20267.334NONO
View all 28 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products28 CVEs
32%
57%
11%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local2 (7.1%)
Network26 (92.9%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low27 (96.4%)
High1 (3.6%)
Unknown0 (0.0%)
User Interaction
None9 (32.1%)
Unknown0 (0.0%)
Required19 (67.9%)
Privileges Required
Low7 (25.0%)
High0 (0.0%)
None21 (75.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (28 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Pnpm.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Pnpm — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Pnpm's Products

View all 2 CNAs →

Top CWEs