Количество 4
Количество 4
CVE-2026-55487
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3.
CVE-2026-55487
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3.
CVE-2026-55487
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic pe ...
GHSA-5wx6-mg75-v57r
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-55487 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-55487 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3. | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
CVE-2026-55487 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic pe ... | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад | |
GHSA-5wx6-mg75-v57r pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle | CVSS3: 7.5 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу