PT-2026-1941 · Pnpm · Pnpm
Published
2026-01-07
·
Updated
2026-05-13
·
CVE-2025-69264
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pnpm versions 10.0.0 through 10.25
Description
pnpm is a package manager affected by an issue where git-hosted dependencies can execute arbitrary code during the
pnpm install process. This bypasses the security feature introduced in version 10, which disables dependency lifecycle scripts execution by default. Specifically, while pnpm version 10 blocks postinstall scripts, git dependencies can still execute prepare, prepublish, and prepack scripts during the fetch phase, potentially leading to remote code execution without user consent.Recommendations
Update to pnpm version 10.26.0 or later.
Exploit
Fix
RCE
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pnpm