Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55487

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 7.5

Описание

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3.

A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to bypass security checks by manipulating how package source strings are processed. By crafting a specially designed source string, an attacker could trick the system into approving and using a malicious package instead of the intended one. This could lead to the execution of unauthorized code or the installation of harmful software, severely impacting the confidentiality, integrity, and availability of the system.

Отчет

This Important vulnerability in pnpm allows an attacker to bypass security checks by manipulating package source strings. This could lead to the execution of unauthorized code or the installation of malicious software. The flaw arises from the package manager's normalization of opaque locators, where an approved source string could inadvertently authorize a different, attacker-controlled source.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-140
https://bugzilla.redhat.com/show_bug.cgi?id=2493035pnpm: pnpm: Supply chain compromise via manipulated package source strings

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3.

CVSS3: 7.5
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic pe ...

CVSS3: 7.5
github
около 1 месяца назад

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

7.5 High

CVSS3