Insufficient verification of data authenticity in pnpm - #VU153374
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to cause installation of config dependencies without registry verification.
The vulnerability exists due to missing dependency authenticity verification in locked config dependency installation when processing config dependencies from a lockfile. A local user can supply a lockfile containing config dependencies that a victim installs to cause installation of config dependencies without registry verification.
Config dependencies are not restricted to npm registry sources.