pnpm
18 known vulnerabilities · 0 critical · 2 high
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
pnpm vulnerable to Command Injection via environment variable substitution
pnpm has Path Traversal via arbitrary file permission modification
pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion
pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
pnpm incorrectly parses tar archives relative to specification
Malicious code in ship_sleepnpm-tool (npm)
Malicious code in pnpm-local-install (npm)
Malicious code in pnpm-run (npm)
OpenClaw: pnpm dlx approvals did not bind local script operands
Malicious code in pnpm-workspaces (npm)
Malicious code in @antv/semantic-release-pnpm (npm)
Malicious code in pnpm-sync-api-tests (npm)