Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Dsherret

#39105of 56,336
7.5Total CVSS
Vulnerabilities · 1
PT-2026-52512
7.5
2026-06-25
Pnpm · Pnpm · CVE-2026-48995
**Name of the Vulnerable Software and Affected Versions** pnpm versions prior to 10.33.4 pnpm versions prior to 11.0.7 **Description** A flaw exists where the package manager does not store the hash of dependencies sourced from `codeload.github.com` in the lockfile. Consequently, a compromised server or machine configuration could allow a malicious server to serve arbitrary tarballs that the software would install regardless of the lockfile's state. **Recommendations** Update to version 10.33.4 or later. Update to version 11.0.7 or later.