Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:brew/pnpm

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A path traversal vulnerability in pnpm prior to 10.34.5 and from 11.0.0 until 11.11.0 allows attacker-controlled package names in pnpm-lock.yaml to write files outside the node_modules directory during installation. This can lead to arbitrary code execution if lifecycle scripts are permitted. The issue is fixed in versions 10.34.5 and 11.11.0.

Join the discussion

A vulnerability in pnpm prior to versions 10.34.5 and 11.11.0 allows a tarball dependency's manifest name to perform path traversal outside node_modules during installation. This leads to arbitrary file write or overwrite on the filesystem, potentially replacing critical files such as shell startup scripts, Git hooks, or installed package code, which can result in code execution. The issue arises because slash characters are not properly rejected in scoped package names, enabling crafted package manifests to escape intended directories. This vulnerability is fixed in pnpm versions 10.34.5 and 11.11.0.

Join the discussion

pnpm versions prior to 9.15.0 have a vulnerability where overrides and global cache handling allow one workspace to poison the global cache and execute scripts in another workspace, even when 'ignore-scripts' is enabled. This breaks user expectations about script execution prevention during installs. The issue is fixed in version 9.15.0. A workaround is to use separate cache and store directories per workspace.

Join the discussion

pnpm versions 6.25.0 through 10.26.2 contain a Command Injection vulnerability via environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker with control over environment variables during pnpm operations could execute remote code in build environments. This vulnerability is fixed in version 10.27.0.

Join the discussion

pnpm versions 10.26.2 and below have a vulnerability where HTTP and git-hosted tarball dependencies are stored in the lockfile without integrity hashes. This allows a remote server to serve different code on each install, bypassing lockfile protections. An attacker publishing a package with such dependencies can serve varying code to different users or CI/CD environments. The issue is fixed starting from version 10.26.0.

Join the discussion

pnpm versions 10.0.0 through 10.25 contain a vulnerability that allows git-hosted dependencies to execute arbitrary code during installation, bypassing the security feature that disables dependency lifecycle scripts by default. This occurs because git dependencies can run prepare, prepublish, and prepack scripts during the fetch phase, enabling remote code execution without user consent. The issue is resolved in pnpm version 10.26.0.

Join the discussion

A path traversal vulnerability in pnpm's binary fetcher prior to version 10.28.1 allows malicious ZIP packages to write files outside the intended extraction directory. This can occur via crafted ZIP entries with '../' or absolute paths, or by manipulating the BinaryResolution.prefix field. The vulnerability can lead to overwriting sensitive files and potentially remote code execution. The issue is patched in version 10.28.1.

Join the discussion

pnpm versions prior to 10.28.1 contain a Windows-specific path traversal vulnerability in tarball extraction. The flaw arises because path normalization only checks for './' but not for Windows-style backslashes '\\', allowing malicious packages to write files outside the intended package directory on Windows systems. This can lead to overwriting critical files such as .npmrc or build configuration files, impacting Windows users and CI/CD pipelines using Windows runners. The issue is patched in version 10.28.1.

Join the discussion

A path traversal vulnerability in pnpm prior to version 10.28.1 allows malicious npm packages to create executable files outside the intended node_modules/.bin directory. This occurs because bin names starting with '@' bypass validation, and path traversal sequences remain after scope normalization. The vulnerability can lead to overwriting configuration files, scripts, or other sensitive files. The issue is patched in pnpm version 10.28.1.

Join the discussion

pnpm versions prior to 10.28.2 have a symlink traversal vulnerability affecting file: and git: dependencies. When installing these dependencies, pnpm follows symlinks without restricting access to the package root, allowing a malicious package to cause local files (e.g., /etc/passwd, ~/.ssh/id_rsa) to be copied into node_modules. This can lead to local data leakage and credential theft. Registry packages are not affected. The issue is patched in version 10.28.2.

Join the discussion

Showing 1 to 10 of 27 results

Filters:Package: pkg:brew/pnpm
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses