PT-2026-52517 · Pnpm · Pnpm
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
pnpm versions prior to 10.34.0
pnpm versions prior to 11.4.0
Description
The tarball extraction worker in the pnpm package manager fails to perform integrity verification when the
integrity field is missing from the lockfile resolution. This creates a fail-open gap where an attacker who can modify the pnpm-lock.yaml file to remove the integrity field and control the content served by the registry URL can force pnpm install --frozen-lockfile to install altered packages without triggering an integrity error.Recommendations
Update to version 10.34.0 or later.
Update to version 11.4.0 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pnpm