Количество 4
Количество 4
CVE-2026-48995
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.
CVE-2026-48995
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.
CVE-2026-48995
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious co ...
GHSA-hg3w-7f8c-63hp
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-48995 pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48995 pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-48995 pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious co ... | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-hg3w-7f8c-63hp pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу