Description
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm-s tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolution. If an attacker can both modify pnpm-lock.yaml to remove the integrity: field and cause the referenced registry URL to serve altered package content, pnpm install --frozen-lockfile can install the altered package without an integrity error. npm-s npm ci enforces integrity by default; pnpm-s behavior of silently skipping verification is a pnpm-specific fail-open gap. This vulnerability is fixed in 10.34.0 and 11.4.0.
CVSS 6.8EPSS 0.174%Risk 0.69
View source- Published
- 2026-06-25 18:16:39
- Affected versions
- <10.34.0,<11.4.0
- Type
- Library
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N