Insufficient verification of data authenticity in pnpm - #VU153376
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to bypass registry verification of lockfile resolutions.
The vulnerability exists due to incomplete resolution authenticity verification in lockfile verification when processing variations resolutions. A local user can supply a lockfile containing unchecked tarballs within a variations resolution or an empty variations resolution for a name@version entry that a victim processes to bypass registry verification of lockfile resolutions.