NIXPKGS-2026-1994
GitHub issue
published 2 months, 2 weeks ago
pnpm: security issues < 11.5.3, < 10.34.2
Permalink
CVE-2026-55487
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- pnpmBuildHook
- pnpmConfigHook
- pnpm-fixup-state-db
- pnpm-shell-completion
- @LeSuisse accepted
- @LeSuisse published on GitHub
pnpm: manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
pnpm
- ==>= 11.0.0, < 11.5.3
- ==< 10.34.2
Permalink
CVE-2026-55700
7.1 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): None (N)
- Integrity (I): High (H)
- Availability (A): Low (L)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): None (N)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): Low (L)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
8 packages
- pnpm_8
- pnpm_9
- pnpm_10
- pnpm_10_29_2
- pnpmBuildHook
- pnpmConfigHook
- pnpm-fixup-state-db
- pnpm-shell-completion
- @LeSuisse accepted
- @LeSuisse published on GitHub
pnpm: stage download writes outside destination via manifest version traversal
-
https://github.com/pnpm/pnpm/security/advisories/GHSA-v23m-ccfg-pq9h x_refsource_CONFIRM
-
https://github.com/pnpm/pnpm/pull/12303 x_refsource_MISC
pnpm
- ==>= 11.3.0, < 11.5.3
Permalink
CVE-2026-55698
8.8 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- pnpmBuildHook
- pnpmConfigHook
- pnpm-fixup-state-db
- pnpm-shell-completion
- @LeSuisse accepted
- @LeSuisse published on GitHub
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
-
https://github.com/pnpm/pnpm/security/advisories/GHSA-w466-c33r-3gjp x_refsource_CONFIRM
pnpm
- ==>= 11.0.0, < 11.5.3
- ==< 10.34.2
Permalink
CVE-2026-55180
6.5 MEDIUM
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): Low (L)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): None (N)
- Availability (A): None (N)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): Low (L)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): None (N)
- Modified Availability (MA): None (N)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
4 packages
- pnpm-fixup-state-db
- pnpm-shell-completion
- pnpmConfigHook
- pnpmBuildHook
- @LeSuisse accepted
- @LeSuisse published on GitHub
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
pnpm
- ==>= 11.0.0, < 11.5.3
- ==< 10.34.2
Permalink
CVE-2026-55697
7.5 HIGH
- CVSS version (CVSS): 3.1
- Attack Vector (AV): Network (N)
- Attack Complexity (AC): High (H)
- Privileges Required (PR): None (N)
- User Interaction (UI): Required (R)
- Scope (S): Unchanged (U)
- Confidentiality (C): High (H)
- Integrity (I): High (H)
- Availability (A): High (H)
- Modified Attack Vector (MAV): Network (N)
- Modified Attack Complexity (MAC): High (H)
- Modified Privileges Required (MPR): None (N)
- Modified User Interaction (MUI): Required (R)
- Modified Confidentiality (MC): High (H)
- Modified Scope (MS): Unchanged (U)
- Modified Integrity (MI): High (H)
- Modified Availability (MA): High (H)
by @LeSuisse Activity log
- Created suggestion
-
@LeSuisse
ignored
5 packages
- pnpm_10_29_2
- pnpmBuildHook
- pnpmConfigHook
- pnpm-fixup-state-db
- pnpm-shell-completion
- @LeSuisse accepted
- @LeSuisse published on GitHub
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
-
https://github.com/pnpm/pnpm/security/advisories/GHSA-gj8w-mvpf-x27x x_refsource_CONFIRM
pnpm
- ==>= 11.0.0, < 11.5.3
- ==< 10.34.2