Protection Mechanism Failure in pnpm - CVE-2025-69264
Published: April 27, 2026
pnpm
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to protection mechanism failure in git dependency lifecycle script handling when processing git-hosted dependencies during pnpm install. A remote attacker can supply a specially crafted git-hosted dependency to execute arbitrary code.
User interaction is required to run pnpm install on a project that includes the malicious dependency.