PT-2026-52517 · Pnpm · Pnpm

·

CVE-2026-50021

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pnpm versions prior to 10.34.0 pnpm versions prior to 11.4.0
Description The tarball extraction worker in the pnpm package manager fails to perform integrity verification when the integrity field is missing from the lockfile resolution. This creates a fail-open gap where an attacker who can modify the pnpm-lock.yaml file to remove the integrity field and control the content served by the registry URL can force pnpm install --frozen-lockfile to install altered packages without triggering an integrity error.
Recommendations Update to version 10.34.0 or later. Update to version 11.4.0 or later.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-50021
GHSA-Q6J5-FJX5-2MC3

Affected Products

Pnpm