#VU107994 Reversible One-Way Hash in pnpm - CVE-2024-47829
Published: April 28, 2025
pnpm
pnpm
Description
The vulnerability allows a remote attacker to overwrite existing packages on the system.
The vulnerability exists due to software pnpm uses md5 function as a path shortening compression function, which can cause collisions in path names. A remote attacker can trick the victim into installing a specially crafted package and overwrite existing packages on the system.