PT-2026-52512 · Pnpm · Pnpm

·

CVE-2026-48995

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

7.5

High

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pnpm versions prior to 10.33.4 pnpm versions prior to 11.0.7
Description A flaw exists where the package manager does not store the hash of dependencies sourced from codeload.github.com in the lockfile. Consequently, a compromised server or machine configuration could allow a malicious server to serve arbitrary tarballs that the software would install regardless of the lockfile's state.
Recommendations Update to version 10.33.4 or later. Update to version 11.0.7 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48995
GHSA-HG3W-7F8C-63HP

Affected Products

Pnpm