Insufficient verification of data authenticity in pnpm - #VU153381
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to bypass registry verification of config dependencies.
The vulnerability exists due to missing registry verification in config dependency installation when processing locked config dependencies. A local user can supply a lockfile specifying an unverified config dependency to bypass registry verification of config dependencies.