Two high-severity vulnerabilities in pnpm exposed developers to supply-chain compromise through routine package installation and automatic package-manager switching. CVE-2026-55698 affects versions before 10.34.2 and 11.5.3 and allows a malicious repository to poison metadata in the first YAML document of pnpm-lock.yaml, causing direct pnpm execution to trust lockfile-selected package-manager artifacts and run attacker-chosen pnpm bytes. The vulnerable flow reached package-manager installation and execution during auto-switching, and the fix forces fresh resolution of package-manager entries from trusted registries before execution.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
11 events from the most recent confirmed update back to the earliest known activity.
A security advisory described a directory traversal and directory hijacking vulnerability in pnpm and its Rust port pacquet during headless installs with hoisted node-linker topology and an untrusted pnpm-lock.yaml. The issue allows malicious dependency alias keys from the lockfile to escape intended module paths and interfere with files or executable paths under node_modules, and the advisory says it was fixed by replacing insecure path joining with boundary-checked path handling.
A security advisory described a pnpm path traversal vulnerability in patch-remove that can be exploited to delete arbitrary files accessible to the pnpm process. The write-up highlighted elevated risk in CI/CD environments and showed a mitigation using an isSubdirectory check to keep patch file paths within the configured patches directory.
A pnpm vulnerability in the configDependencies installation flow allowed crafted dependency names or versions to abuse path construction under node_modules/.pnpm-config for path traversal and arbitrary symlink creation. The issue was remediated by adding strict validation for configuration dependency names and exact semantic versions before filesystem operations, with the fix implemented in commit 352ae489f1b14ffdc19d2c6eacb1b06b098c2ddc.
CVE-2026-55699 was published as a pnpm path traversal and arbitrary recursive deletion vulnerability in global package management operations. The issue stems from improper sanitization of package.json bin-map keys, allowing values like ".." to escape the global binary directory and be passed to fs.rmSync with recursive deletion during operations such as pnpm global remove.
CVE-2026-55700 was disclosed as a pnpm path traversal and arbitrary file write vulnerability in the `pnpm stage download` command, where crafted package manifest `name` and `version` fields from a malicious or compromised registry could cause writes outside the intended download directory. The report says versions earlier than 11.5.3 are affected and that the issue was fixed by validating package names and semantic versions and enforcing path containment checks.
The CVE record states the lockfile-based package-manager execution vulnerability was fixed in pnpm versions 10.34.2 and 11.5.3. These versions remediate the unsafe trust of env lockfile package-manager metadata.
CVE-2026-55698 was published as a high-severity remotely exploitable supply-chain vulnerability in pnpm affecting versions prior to 10.34.2 and 11.5.3. The flaw lets a malicious repository abuse package-manager bootstrap metadata in pnpm-lock.yaml to short-circuit fresh resolution and execute attacker-selected pnpm bytes during automatic version switching.
The CVE record states the transitive dependency alias path traversal issue was fixed in pnpm versions 10.34.0 and 11.4.0. These releases address the project path override via symlink replacement vulnerability.
CVE-2026-50016 was published as a high-severity remotely exploitable pnpm vulnerability affecting versions prior to 10.34.0 and 11.4.0. The issue allows malicious registry metadata in a transitive dependency alias to trigger path traversal and replace project paths with symlinks even when users run pnpm install --ignore-scripts.
A GitHub security advisory disclosed a high-severity pnpm supply-chain vulnerability in which malicious package-manager metadata in pnpm-lock.yaml could bypass fresh resolution during automatic version switching and lead to execution of attacker-selected pnpm bytes. The advisory states the patch forces re-resolution through trusted registries before installation and execution.
A GitHub security advisory described a path traversal flaw in pnpm where a malicious transitive dependency alias could escape node_modules and replace project paths with symlinks to attacker-controlled directories. The write-up included a proof of concept targeting .git/hooks to achieve delayed code execution on a later git commit.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
9 references tracked. Mallory keeps watching after this page renders.
cvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvereports.com
Open sourcecvefeed.io
Open sourcecvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.