SB2026100659 - Multiple vulnerabilities in pnpm
Published: October 6, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 27 vulnerabilities.
1) Argument injection (CVE-ID: N/A)
CWE-ID: CWE-88 - Argument Injection or Modification
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to inject command-line options into git dependency processing.
The vulnerability exists due to improper neutralization of command-line arguments in git dependency handling when processing a repository value from a lockfile. A local user can supply a repository value that git interprets as a command-line option to inject command-line options into git dependency processing.
The advisory identifies empty repository values, values beginning with a hyphen, and values containing a null byte as problematic inputs.
2) Inclusion of Sensitive Information in Log Files (CVE-ID: N/A)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose registry usernames and passwords.
The vulnerability exists due to inclusion of sensitive information in warning output when reporting ignored project .npmrc registry and authentication settings. A local user can read warnings containing credentials from URL-scoped configuration keys to disclose registry usernames and passwords.
The exposed credentials are embedded in the URL portion of a configuration key, such as //user:password@registry.example.com/:_authToken.
3) Improper Neutralization of Escape, Meta, or Control Sequences (CVE-ID: N/A)
CWE-ID: CWE-150 - Improper Neutralization of Escape, Meta, or Control Sequences
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject terminal control characters into license table output.
The vulnerability exists due to improper neutralization of terminal control characters in pnpm licenses table rendering when displaying package metadata. A remote attacker can supply package metadata containing terminal control characters to inject terminal control characters into license table output.
4) Improper Handling of Case Sensitivity (CVE-ID: N/A)
CWE-ID: CWE-178 - Improper Handling of Case Sensitivity
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to make distinct dependencies share a virtual store directory.
The vulnerability exists due to ambiguous dependency identifier encoding in virtual store directory naming when mapping URL or local path dependencies to directory names. A remote attacker can supply a dependency identifier with +, #, :, or ? where another identifier has / to make distinct dependencies share a virtual store directory.
Git dependencies pinned with # are also within the scope of this issue.
5) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to consume excessive memory during package publication.
The vulnerability exists due to insufficient limits on memory consumption in pnpm publish tarball metadata handling when reading oversized manifests or README files from pre-built tarballs into memory. A remote attacker can supply a pre-built tarball containing such files to consume excessive memory during package publication.
6) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to consume excessive memory while package metadata is processed.
The vulnerability exists due to insufficient limits on memory consumption in package manifest and archive metadata processing when reading oversized manifests or archive metadata during installation. A remote attacker can supply a package containing oversized metadata to consume excessive memory while package metadata is processed.
7) Resource exhaustion (CVE-ID: N/A)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to consume excessive memory during package installation.
The vulnerability exists due to unbounded memory consumption in compressed package archive processing when handling large files inside gzip or bzip2 package archives. A remote attacker can supply an archive containing excessively large files to consume excessive memory during package installation.
8) Resource exhaustion (CVE-ID: N/A)
CWE-ID: CWE-400 - Resource exhaustion
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to consume excessive memory during package installation.
The vulnerability exists due to unbounded memory consumption in package download handling when downloading large packages for installation. A remote attacker can supply an excessively large package download to consume excessive memory during package installation.
9) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper handling of large archive entries in package archive processing when reading an entry of 4 GiB or more. A remote attacker can supply a package archive containing such an entry to cause a denial of service.
Processing the archive can cause pnpm to hang.
10) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper validation of record lengths in package archive PAX record processing when parsing a negative PAX record length. A remote attacker can supply a package archive containing such a record to cause a denial of service.
Processing the archive can cause pnpm to hang.
11) UNIX symbolic link following (CVE-ID: N/A)
CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to include files from outside a package directory during deployment or local installation.
The vulnerability exists due to improper symbolic link resolution in package deployment and local package installation when following package symlinks. A local user can provide a package symlink pointing outside the package directory to include files from outside a package directory during deployment or local installation.
Exploitation requires the deployAllFiles setting to be enabled.
12) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to include files from outside a package directory through bundled dependencies.
The vulnerability exists due to improper restriction of file paths in bundled dependency file collection when packing, publishing, or installing git and local directory dependencies. A remote attacker can supply a package with a bundleDependencies entry pointing outside its directory to include files from outside a package directory through bundled dependencies.
13) UNIX symbolic link following (CVE-ID: N/A)
CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to include files from outside a package directory in package operations.
The vulnerability exists due to improper symbolic link resolution in package file collection when packing, publishing, or installing git and local directory dependencies. A remote attacker can supply a package containing a directory symlink pointing outside its directory to include files from outside a package directory in package operations.
14) UNIX symbolic link following (CVE-ID: N/A)
CWE-ID: CWE-61 - UNIX Symbolic Link (Symlink) Following
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to access files outside a git dependency repository.
The vulnerability exists due to improper symbolic link resolution in git dependency subpath handling when processing a dependency with a #path: subpath. A remote attacker can supply a git dependency containing a symlink in that subpath to access files outside a git dependency repository.
15) Path traversal (CVE-ID: N/A)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to write files outside the global virtual store.
The vulnerability exists due to path traversal in dependency version handling in pnpm install when processing dependency versions. A remote attacker can supply a dependency version containing path traversal sequences that a victim installs to write files outside the global virtual store.
16) Improper Verification of Cryptographic Signature (CVE-ID: N/A)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass signature verification tied to lockfile integrity.
The vulnerability exists due to improper signature verification in pnpm audit signatures when verifying packages against the integrity recorded in a lockfile. A local user can supply a lockfile with missing or mismatched package integrity to bypass signature verification tied to lockfile integrity.
17) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make lockfile verification accept an invalid dependency resolution.
The vulnerability exists due to improper validation of empty resolutions in lockfile verification when processing a name@version entry with an empty variations resolution. A local user can supply such an entry in a lockfile to make lockfile verification accept an invalid dependency resolution.
18) Insufficient verification of data authenticity (CVE-ID: N/A)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass registry verification of dependency tarballs.
The vulnerability exists due to missing registry verification in lockfile variations resolution verification when checking tarballs inside a variations resolution. A local user can supply a lockfile containing unverified tarballs in that resolution to bypass registry verification of dependency tarballs.
19) Improper validation of integrity check value (CVE-ID: N/A)
CWE-ID: CWE-354 - Improper Validation of Integrity Check Value
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to override the pinned integrity of a config dependency.
The vulnerability exists due to improper enforcement of pinned integrity in config dependency resolution when processing a lockfile for a dependency pinned with version+integrity. A local user can replace the dependency's integrity in the lockfile to override the pinned integrity of a config dependency.
20) Insufficient verification of data authenticity (CVE-ID: N/A)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass registry verification of config dependencies.
The vulnerability exists due to missing registry verification in config dependency installation when processing locked config dependencies. A local user can supply a lockfile specifying an unverified config dependency to bypass registry verification of config dependencies.
21) Inclusion of Sensitive Information in Log Files (CVE-ID: N/A)
CWE-ID: CWE-532 - Information Exposure Through Log Files
CVSSv4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to obtain registry usernames and passwords from warning output.
The vulnerability exists due to inclusion of sensitive information in warning output in project .npmrc registry warnings when reporting an ignored registry setting containing a URL-scoped key with embedded credentials. A local user can read the emitted warning to obtain registry usernames and passwords from warning output.
22) Improper Resolution of Path Equivalence (CVE-ID: N/A)
CWE-ID: CWE-41 - Improper Resolution of Path Equivalence
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make distinct dependencies share a virtual store directory.
The vulnerability exists due to improper resolution of path equivalence in virtual store directory naming when deriving directory names for URL or local path dependencies. A local user can supply dependency references that differ by +, #, :, or ? in one reference and / in another to make distinct dependencies share a virtual store directory.
Git dependencies pinned with # are also subject to these directory-name collisions.
23) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service through excessive memory consumption.
The vulnerability exists due to unrestricted memory allocation in archive metadata processing in pnpm install and pnpm publish when reading archive metadata into memory. A remote attacker can supply a tarball with oversized metadata that a victim installs or publishes to cause a denial of service through excessive memory consumption.
Publishing a pre-built tarball also processes oversized manifests and README files.
24) Improper Verification of Cryptographic Signature (CVE-ID: N/A)
CWE-ID: CWE-347 - Improper Verification of Cryptographic Signature
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to make packages pass signature verification without validation against their lockfile integrity.
The vulnerability exists due to improper cryptographic signature verification in pnpm audit signatures when verifying package signatures. A local user can supply package entries with mismatched or missing lockfile integrity that a victim audits to make packages pass signature verification without validation against their lockfile integrity.
25) Insufficient verification of data authenticity (CVE-ID: N/A)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to bypass registry verification of lockfile resolutions.
The vulnerability exists due to incomplete resolution authenticity verification in lockfile verification when processing variations resolutions. A local user can supply a lockfile containing unchecked tarballs within a variations resolution or an empty variations resolution for a name@version entry that a victim processes to bypass registry verification of lockfile resolutions.
26) Improper validation of integrity check value (CVE-ID: N/A)
CWE-ID: CWE-354 - Improper Validation of Integrity Check Value
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to override the pinned integrity of a config dependency.
The vulnerability exists due to improper enforcement of pinned integrity values in config dependency integrity handling when processing a lockfile for a config dependency pinned with version+integrity. A local user can supply a lockfile containing a replacement integrity value that a victim uses during installation to override the pinned integrity of a config dependency.
27) Insufficient verification of data authenticity (CVE-ID: N/A)
CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity
CVSSv4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to cause installation of config dependencies without registry verification.
The vulnerability exists due to missing dependency authenticity verification in locked config dependency installation when processing config dependencies from a lockfile. A local user can supply a lockfile containing config dependencies that a victim installs to cause installation of config dependencies without registry verification.
Config dependencies are not restricted to npm registry sources.
Remediation
Install update from vendor's website.
References
- https://github.com/pnpm/pnpm/releases/tag/v11.28.5
- https://github.com/pnpm/tasks/issues/84
- https://github.com/pnpm/tasks/issues/79
- https://github.com/pnpm/tasks/issues/78
- https://github.com/pnpm/tasks/issues/93
- https://github.com/pnpm/tasks/issues/83
- https://github.com/pnpm/pnpm/releases/tag/v12.10.0