Improper validation of integrity check value in pnpm - #VU153375
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to override the pinned integrity of a config dependency.
The vulnerability exists due to improper enforcement of pinned integrity values in config dependency integrity handling when processing a lockfile for a config dependency pinned with version+integrity. A local user can supply a lockfile containing a replacement integrity value that a victim uses during installation to override the pinned integrity of a config dependency.