Origin validation error in pnpm - CVE-2026-55487

 

Origin validation error in pnpm - CVE-2026-55487

Published: June 15, 2026


Vulnerability identifier: #VU134551
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55487
CWE-ID: CWE-346
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to origin validation error in the allowBuilds build policy when processing opaque dependency locators. A remote attacker can supply a specially crafted dependency source string that collides with an approved locator to execute arbitrary code.

User interaction is required to approve the dependency source and run the lifecycle script.


Affected software

pnpm

How to mitigate CVE-2026-55487

Install security update from vendor's website.

pnpm - addressed in versions 11.0.0, 11.5.3

External References

Related Security Bulletins