pnpm
17 known vulnerabilities · 0 critical · 2 high
pnpm vulnerable to Command Injection via environment variable substitution
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
pnpm has Path Traversal via arbitrary file permission modification
pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion
pnpm incorrectly parses tar archives relative to specification
pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
Malicious code in pnpm-sync-api-tests (npm)
Malicious code in ship_sleepnpm-tool (npm)
Malicious code in pnpm-local-install (npm)
Malicious code in pnpm-run (npm)
OpenClaw: pnpm dlx approvals did not bind local script operands
Malicious code in pnpm-workspaces (npm)