pnpm kayıtları
pnpm üreticisine ait 28 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 3
- Düzeltme kaydı olan
- %100
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')10
- CWE-345 Insufficient Verification of Data Authenticity2
- CWE-426 Untrusted Search Path2
- CWE-23 Relative Path Traversal2
- CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')2
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
28 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
39İzleyin | CVE-2023-37478Kavram kanıtı | pnpm incorrectly parses tar archives relative to specificationpnpm · pnpm · CWE-284 | Kritik9,8 | — | %1,2 | 1 Ağu 2023 |
39İzleyin | CVE-2025-69264İstismar yok | pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"pnpm · pnpm · CWE-693 | Kritik9,8 | — | %1,0 | 7 Oca 2026 |
35İzleyin | CVE-2022-26183İstismar yok | PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when usepnpm · pnpm · CWE-426 | Yüksek8,8 | — | %1,6 | 21 Mar 2022 |
35İzleyin | CVE-2026-50016İstismar yok | pnpm: Transitive dependency alias path traversal allows project path override via symlink replacementpnpm · pnpm · CWE-23 | Yüksek8,8 | — | %0,5 | 25 Haz 2026 |
35İzleyin | CVE-2025-69263İstismar yok | pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependenciespnpm · pnpm · CWE-494 | Yüksek8,8 | — | %0,5 | 7 Oca 2026 |
35İzleyin | CVE-2026-55698İstismar yok | pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytespnpm · pnpm · CWE-345 | Yüksek8,8 | — | %0,3 | 25 Haz 2026 |
35İzleyin | CVE-2026-55697İstismar yok | pnpm: Repository-controlled configDependencies can select a pacquet native install enginepnpm · pnpm · CWE-78 | Yüksek8,8 | — | %0,2 | 25 Haz 2026 |
35İzleyin | CVE-2026-55487İstismar yok | pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecyclepnpm · pnpm · CWE-346 | Yüksek8,8 | — | %0,2 | 25 Haz 2026 |
32İzleyin | CVE-2026-59195İstismar yok | pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-configpnpm · pnpm · CWE-22 | Yüksek8,2 | — | %0,4 | 6 Tem 2026 |
32İzleyin | CVE-2026-50021İstismar yok | pnpm: Integrity Check Bypass via Missing Lockfile Integrity Fieldpnpm · pnpm · CWE-354 | Yüksek8,1 | — | %0,2 | 25 Haz 2026 |
32İzleyin | CVE-2026-50573İstismar yok | pnpm: Unsafe default behavior breaks integrity checkpnpm · pnpm · CWE-345 | Yüksek8,1 | — | %0,2 | 25 Haz 2026 |
31İzleyin | CVE-2025-69262İstismar yok | pnpm vulnerable to Command Injection via environment variable substitutionpnpm · pnpm · CWE-78 | Yüksek7,8 | — | %1,1 | 7 Oca 2026 |
29İzleyin | CVE-2026-50015İstismar yok | pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)pnpm · pnpm · CWE-22 | Yüksek7,3 | — | %0,4 | 25 Haz 2026 |
29İzleyin | CVE-2026-50014İstismar yok | pnpm: Git Fetch Argument Injection via Lockfile resolution.commitpnpm · pnpm · CWE-88 | Yüksek7,3 | — | %0,3 | 25 Haz 2026 |
28İzleyin | CVE-2026-55700İstismar yok | pnpm: stage download writes outside destination via manifest version traversalpnpm · pnpm · CWE-22 | Yüksek7,1 | — | %0,4 | 25 Haz 2026 |
28İzleyin | CVE-2026-59196İstismar yok | pnpm: hoisted install imports lockfile alias outside node_modulespnpm · pnpm · CWE-22 | Yüksek7,1 | — | %0,4 | 6 Tem 2026 |
28İzleyin | CVE-2026-59194İstismar yok | pnpm: patch-remove could delete project-selected files outside the patches directorypnpm · pnpm · CWE-22 | Yüksek7,1 | — | %0,4 | 6 Tem 2026 |
27İzleyin | CVE-2026-50017İstismar yok | pnpm binds unscoped user-level npm auth credentials to a repository-selected registrypnpm · pnpm · CWE-200 | Orta6,9 | — | %0,4 | 25 Haz 2026 |
26İzleyin | CVE-2026-24056İstismar yok | pnpm has symlink traversal in file:/git dependenciespnpm · pnpm · CWE-22 | Orta6,7 | — | %0,5 | 26 Oca 2026 |
26İzleyin | CVE-2026-23890İstismar yok | pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.binpnpm · pnpm · CWE-23 | Orta6,5 | — | %0,5 | 26 Oca 2026 |
26İzleyin | CVE-2026-23889İstismar yok | pnpm has Windows-specific tarball Path Traversalpnpm · pnpm · CWE-22 | Orta6,5 | — | %0,5 | 26 Oca 2026 |
26İzleyin | CVE-2026-23888İstismar yok | pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)pnpm · pnpm · CWE-22 | Orta6,5 | — | %0,5 | 26 Oca 2026 |
26İzleyin | CVE-2026-55699İstismar yok | pnpm: reserved bin name deletes PNPM_HOME during global removepnpm · pnpm · CWE-22 | Orta6,5 | — | %0,5 | 25 Haz 2026 |
26İzleyin | CVE-2026-55180İstismar yok | pnpm: Repository config can expand victim environment secrets into registry requests before scripts runpnpm · pnpm · CWE-200 | Orta6,5 | — | %0,4 | 25 Haz 2026 |
26İzleyin | CVE-2026-24131İstismar yok | pnpm has Path Traversal via arbitrary file permission modificationpnpm · pnpm · CWE-22 | Orta6,7 | — | %0,3 | 26 Oca 2026 |
- CVE-2023-3747839İzleyin
pnpm incorrectly parses tar archives relative to specification
KritikCVSS 9,8Kavram kanıtıEPSS %1pnpm · pnpm1 Ağu 2023
- CVE-2025-6926439İzleyin
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
KritikCVSS 9,8İstismar yokEPSS %1pnpm · pnpm7 Oca 2026
- CVE-2022-2618335İzleyin
PNPM v6.15.1 and below was discovered to contain an untrusted search path which causes the application to behave in unexpected ways when use
YüksekCVSS 8,8İstismar yokEPSS %2pnpm · pnpm21 Mar 2022
- CVE-2026-5001635İzleyin
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
YüksekCVSS 8,8İstismar yokEPSS %1pnpm · pnpm25 Haz 2026
- CVE-2025-6926335İzleyin
pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies
YüksekCVSS 8,8İstismar yokEPSS %0pnpm · pnpm7 Oca 2026
- CVE-2026-5569835İzleyin
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
YüksekCVSS 8,8İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5569735İzleyin
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
YüksekCVSS 8,8İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5548735İzleyin
pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
YüksekCVSS 8,8İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5919532İzleyin
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
YüksekCVSS 8,2İstismar yokEPSS %0pnpm · pnpm6 Tem 2026
- CVE-2026-5002132İzleyin
pnpm: Integrity Check Bypass via Missing Lockfile Integrity Field
YüksekCVSS 8,1İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5057332İzleyin
pnpm: Unsafe default behavior breaks integrity check
YüksekCVSS 8,1İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2025-6926231İzleyin
pnpm vulnerable to Command Injection via environment variable substitution
YüksekCVSS 7,8İstismar yokEPSS %1pnpm · pnpm7 Oca 2026
- CVE-2026-5001529İzleyin
pnpm: Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
YüksekCVSS 7,3İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5001429İzleyin
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
YüksekCVSS 7,3İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5570028İzleyin
pnpm: stage download writes outside destination via manifest version traversal
YüksekCVSS 7,1İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5919628İzleyin
pnpm: hoisted install imports lockfile alias outside node_modules
YüksekCVSS 7,1İstismar yokEPSS %0pnpm · pnpm6 Tem 2026
- CVE-2026-5919428İzleyin
pnpm: patch-remove could delete project-selected files outside the patches directory
YüksekCVSS 7,1İstismar yokEPSS %0pnpm · pnpm6 Tem 2026
- CVE-2026-5001727İzleyin
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
OrtaCVSS 6,9İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-2405626İzleyin
pnpm has symlink traversal in file:/git dependencies
OrtaCVSS 6,7İstismar yokEPSS %1pnpm · pnpm26 Oca 2026
- CVE-2026-2389026İzleyin
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
OrtaCVSS 6,5İstismar yokEPSS %1pnpm · pnpm26 Oca 2026
- CVE-2026-2388926İzleyin
pnpm has Windows-specific tarball Path Traversal
OrtaCVSS 6,5İstismar yokEPSS %0pnpm · pnpm26 Oca 2026
- CVE-2026-2388826İzleyin
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
OrtaCVSS 6,5İstismar yokEPSS %0pnpm · pnpm26 Oca 2026
- CVE-2026-5569926İzleyin
pnpm: reserved bin name deletes PNPM_HOME during global remove
OrtaCVSS 6,5İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-5518026İzleyin
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
OrtaCVSS 6,5İstismar yokEPSS %0pnpm · pnpm25 Haz 2026
- CVE-2026-2413126İzleyin
pnpm has Path Traversal via arbitrary file permission modification
OrtaCVSS 6,7İstismar yokEPSS %0pnpm · pnpm26 Oca 2026