Insufficient verification of data authenticity in pnpm - #VU153383
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to bypass registry verification of dependency tarballs.
The vulnerability exists due to missing registry verification in lockfile variations resolution verification when checking tarballs inside a variations resolution. A local user can supply a lockfile containing unverified tarballs in that resolution to bypass registry verification of dependency tarballs.