Pnpm · Pnpm · CVE-2026-48995
**Name of the Vulnerable Software and Affected Versions**
pnpm versions prior to 10.33.4
pnpm versions prior to 11.0.7
**Description**
A flaw exists where the package manager does not store the hash of dependencies sourced from `codeload.github.com` in the lockfile. Consequently, a compromised server or machine configuration could allow a malicious server to serve arbitrary tarballs that the software would install regardless of the lockfile's state.
**Recommendations**
Update to version 10.33.4 or later.
Update to version 11.0.7 or later.