PT-2026-52522 · Pnpm · Pnpm

·

CVE-2026-55697

·

Published

2026-06-25

·

Updated

2026-07-30

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pnpm versions prior to 10.34.2 pnpm versions prior to 11.5.3
Description pnpm allows the installation of configDependencies declared in pnpm-workspace.yaml before command dispatch. A repository can declare pacquet or @pnpm/pacquet as a config dependency, which pnpm treats as an install-engine opt-in. During the installation process, pnpm resolves a platform-specific @pacquet/<platform>-<arch>/pacquet binary from node modules/.pnpm-config/<packageName> and executes it with the privileges of the developer or CI user.
Recommendations Update pnpm to version 10.34.2 or later. Update pnpm to version 11.5.3 or later.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55697
GHSA-GJ8W-MVPF-X27X

Affected Products

Pnpm