Improper Verification of Cryptographic Signature in pnpm - #VU153377

 

Improper Verification of Cryptographic Signature in pnpm - #VU153377

Published: October 6, 2026


Vulnerability identifier: #VU153377
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-347
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to make packages pass signature verification without validation against their lockfile integrity.

The vulnerability exists due to improper cryptographic signature verification in pnpm audit signatures when verifying package signatures. A local user can supply package entries with mismatched or missing lockfile integrity that a victim audits to make packages pass signature verification without validation against their lockfile integrity.


Affected software

pnpm

Remediation

Install security update from vendor's website.

pnpm - update to 12.10.0

External References

Related Security Bulletins