Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55697

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependency and pnpm treated that repository-controlled dependency as an install-engine opt-in. During install, pnpm resolved a platform-specific @pacquet/-/pacquet binary from node_modules/.pnpm-config/ and spawned it as the developer or CI user. This vulnerability is fixed in 10.34.2 and 11.5.3.

A flaw was found in pnpm, a package manager. A remote attacker could exploit this vulnerability by crafting a malicious repository that declares a configDependency in its pnpm-workspace.yaml file. When a user installs packages from this repository, pnpm improperly treats the declared dependency as an install-engine opt-in, leading to the execution of a malicious binary. This allows for arbitrary code execution on the system of the developer or continuous integration (CI) user.

Отчет

This is an Important arbitrary code execution flaw in pnpm, a package manager. A remote attacker could exploit this by crafting a malicious repository that, when used by a developer or CI system, leads to the execution of a malicious binary. This vulnerability arises from pnpm's improper handling of configDependencies declared in pnpm-workspace.yaml, allowing an untrusted repository to opt into a native install engine.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-349
https://bugzilla.redhat.com/show_bug.cgi?id=2493038pnpm: pnpm: Arbitrary code execution via improper handling of config dependencies

EPSS

Процентиль: 7%
0.00174
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
nvd
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependency and pnpm treated that repository-controlled dependency as an install-engine opt-in. During install, pnpm resolved a platform-specific @pacquet/<platform>-<arch>/pacquet binary from node_modules/.pnpm-config/<packageName> and spawned it as the developer or CI user. This vulnerability is fixed in 10.34.2 and 11.5.3.

CVSS3: 7.5
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can insta ...

CVSS3: 7.5
github
около 1 месяца назад

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

EPSS

Процентиль: 7%
0.00174
Низкий

7.5 High

CVSS3