Input validation error in pnpm - #VU153384
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to make lockfile verification accept an invalid dependency resolution.
The vulnerability exists due to improper validation of empty resolutions in lockfile verification when processing a name@version entry with an empty variations resolution. A local user can supply such an entry in a lockfile to make lockfile verification accept an invalid dependency resolution.