Argument injection in pnpm - #VU153386
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to inject command-line options into git dependency processing.
The vulnerability exists due to improper neutralization of command-line arguments in git dependency handling when processing a repository value from a lockfile. A local user can supply a repository value that git interprets as a command-line option to inject command-line options into git dependency processing.
The advisory identifies empty repository values, values beginning with a hyphen, and values containing a null byte as problematic inputs.