Improper Verification of Cryptographic Signature in pnpm - #VU153377
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to make packages pass signature verification without validation against their lockfile integrity.
The vulnerability exists due to improper cryptographic signature verification in pnpm audit signatures when verifying package signatures. A local user can supply package entries with mismatched or missing lockfile integrity that a victim audits to make packages pass signature verification without validation against their lockfile integrity.