Vulnerabilidades em pnpm
27 resultadosAnálise Vexday
O pnpm apresenta 27 vulnerabilidades catalogadas, com 16 publicadas nos últimos 90 dias, indicando risco em evolução recente. Nenhuma vulnerabilidade crítica ou sob ataque ativo foi registrada até o momento. A fraqueza dominante é CWE-22 (path traversal), que afeta integridade e disponibilidade do gerenciador de pacotes.
CVE-2023-37478HIGHpnpm incorrectly parses tar archives relative to specificationEPSS 1.2%CVE-2025-69264HIGHpnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"EPSS 1.0%CVE-2025-69262HIGHpnpm vulnerable to Command Injection via environment variable substitutionEPSS 1.0%CVE-2024-53866MEDIUMpnpm vulnerable to no-script global cache poisoning via overrides / `ignore-scripts` evasionEPSS 0.9%CVE-2026-50016HIGHpnpm: Transitive dependency alias path traversal allows project path override via symlink replacementEPSS 0.5%CVE-2026-24056MEDIUMpnpm has symlink traversal in file:/git dependenciesEPSS 0.5%CVE-2026-23890MEDIUMpnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.binEPSS 0.4%CVE-2026-23889MEDIUMpnpm has Windows-specific tarball Path TraversalEPSS 0.4%CVE-2025-69263HIGHpnpm Lockfile Integrity Bypass Allows Remote Dynamic DependenciesEPSS 0.4%CVE-2026-55699MEDIUMpnpm: reserved bin name deletes PNPM_HOME during global removeEPSS 0.4%CVE-2026-23888MEDIUMpnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)EPSS 0.4%CVE-2026-50017MEDIUMpnpm binds unscoped user-level npm auth credentials to a repository-selected registryEPSS 0.4%CVE-2026-50015HIGHpnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)EPSS 0.4%CVE-2026-55700HIGHpnpm: stage download writes outside destination via manifest version traversalEPSS 0.4%CVE-2026-55180MEDIUMpnpm: Repository config can expand victim environment secrets into registry requests before scripts runEPSS 0.3%CVE-2026-59196HIGHpnpm: hoisted install imports lockfile alias outside node_modulesEPSS 0.3%CVE-2026-59194HIGHpnpm: patch-remove could delete project-selected files outside the patches directoryEPSS 0.3%CVE-2026-59195HIGHpnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configEPSS 0.3%CVE-2026-55698HIGHpnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytesEPSS 0.3%CVE-2026-50014MEDIUMpnpm: Git Fetch Argument Injection via Lockfile resolution.commitEPSS 0.3%