Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55698

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 8.8

Описание

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env lockfile contained matching pnpm and @pnpm/exe versions. A malicious repository could therefore commit package-manager lockfile package records and snapshots that bypassed fresh package-manager resolution, then cause pnpm to install and execute bytes selected by that committed lockfile state during automatic version switching. This vulnerability is fixed in 10.34.2 and 11.5.3.

A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to achieve arbitrary code execution by committing a specially crafted package-manager lockfile (pnpm-lock.yaml) to a repository. When pnpm is executed, it trusts an already resolved packageManagerDependencies entry, enabling the malicious lockfile to bypass standard package resolution. This can cause pnpm to install and execute attacker-controlled code during automatic version switching.

Отчет

This is an Important arbitrary code execution flaw in pnpm, a package manager used in Red Hat products. The vulnerability arises from pnpm's trust in pre-resolved package manager metadata within pnpm-lock.yaml, allowing a malicious repository to bypass standard package resolution. This can lead to the execution of attacker-controlled code when pnpm is used to install dependencies from such a repository, posing a significant supply chain risk.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmNot affected
Red Hat Build of KeycloakpnpmAffected
Red Hat JBoss Enterprise Application Platform 8pnpmNot affected
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-502
https://bugzilla.redhat.com/show_bug.cgi?id=2493022pnpm: pnpm: Arbitrary code execution via malicious package-manager lockfile

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env lockfile contained matching pnpm and @pnpm/exe versions. A malicious repository could therefore commit package-manager lockfile package records and snapshots that bypassed fresh package-manager resolution, then cause pnpm to install and execute bytes selected by that committed lockfile state during automatic version switching. This vulnerability is fixed in 10.34.2 and 11.5.3.

CVSS3: 8.8
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persi ...

CVSS3: 8.8
github
около 1 месяца назад

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

8.8 High

CVSS3