PT-2026-52521 · Pnpm · Pnpm
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pnpm versions prior to 10.34.2
pnpm versions prior to 11.5.3
Description
The generic peer-suffix normalizer incorrectly strips parenthesized text from git, URL, tarball, file, and other opaque locators. This behavior allows a scenario where approval for one source string could inadvertently authorize a different, attacker-controlled source that normalizes to the same value.
Recommendations
Update to version 10.34.2.
Update to version 11.5.3.
Exploit
Fix
Origin Validation Error
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pnpm