Vulnerabilities
Vulnerable Software
Pnpm:  >> Pnpm  >> 9.15.0  Security Vulnerabilities
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.
CVSS Score
7.5
EPSS Score
0.009
Published
2026-01-07
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.
CVSS Score
6.5
EPSS Score
0.002
Published
2025-04-23


Contact Us

Shodan ® - All rights reserved