PT-2026-52522 · Pnpm · Pnpm
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pnpm versions prior to 10.34.2
pnpm versions prior to 11.5.3
Description
pnpm allows the installation of
configDependencies declared in pnpm-workspace.yaml before command dispatch. A repository can declare pacquet or @pnpm/pacquet as a config dependency, which pnpm treats as an install-engine opt-in. During the installation process, pnpm resolves a platform-specific @pacquet/<platform>-<arch>/pacquet binary from node modules/.pnpm-config/<packageName> and executes it with the privileges of the developer or CI user.Recommendations
Update pnpm to version 10.34.2 or later.
Update pnpm to version 11.5.3 or later.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pnpm