Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-48995

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.

A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to serve malicious software packages if the codeload.github.com server is compromised or a user's machine configuration is tampered with. The issue arises because pnpm does not verify the integrity of dependencies downloaded from https://codeload.github.com against its lockfile. This could lead to the installation of unverified and potentially malicious code, resulting in arbitrary code execution on the affected system.

Отчет

This Important vulnerability in pnpm, as shipped in Red Hat products, exposes users to supply chain attacks by failing to verify the integrity of dependencies sourced from codeload.github.com. If the codeload.github.com server is compromised or a user's local machine configuration is tampered with, pnpm could install malicious software packages without detection, leading to arbitrary code execution. This risk is heightened in environments where developers rely on GitHub git dependencies without additional integrity checks.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-494
https://bugzilla.redhat.com/show_bug.cgi?id=2493032pnpm: pnpm: Supply chain compromise from unverified dependencies

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.

CVSS3: 7.5
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious co ...

github
около 1 месяца назад

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

7.5 High

CVSS3