28 Total advisories
28 Vulnerabilities
0 Malware

Dependency scanning

Check whether pnpm is in your codebase

Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.

Vulnerabilities

HIGH 7.5
npm

CVE-2026-55697

pnpm: Repository-controlled configDependencies can select a pacquet native install engine

HIGH 7.1
npm

CVE-2026-59196

pnpm: Hoisted install imports lockfile alias outside node_modules

HIGH 7.1
npm

CVE-2026-59194

pnpm: `patch-remove` could delete project-selected files outside the patches directory

HIGH 8.2
npm

CVE-2026-59195

pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config

HIGH 7.1
npm

CVE-2026-55700

pnpm: `stage download` writes outside its destination directory via manifest name/version traversal

MEDIUM 6.5
npm

CVE-2026-55699

pnpm: Reserved bin name deletes PNPM_HOME during global remove

HIGH 8.8
npm

CVE-2026-55698

pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes

HIGH 7.5
npm

CVE-2026-55487

pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle

MEDIUM 6.5
npm

CVE-2026-55180

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

HIGH 7.3
npm

CVE-2026-50015

pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)

UNKNOWN
npm

CVE-2026-50017

pnpm binds unscoped user-level npm auth credentials to a repository-selected registry

MEDIUM 6.8
npm

CVE-2026-50573

pnpm: Unsafe default behavior breaks integrity check

MEDIUM 6.4
npm

CVE-2026-50014

pnpm: Git Fetch Argument Injection via Lockfile resolution.commit

HIGH 8.8
npm

CVE-2026-50016

pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement

MEDIUM 6.8
npm

CVE-2026-50021

pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field

UNKNOWN
npm

CVE-2026-48995

pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile

UNKNOWN
npm

CVE-2024-53866

pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion

HIGH 7.5
npm

CVE-2025-69263

pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies

HIGH 8.8
npm

CVE-2025-69264

pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"

HIGH 7.5
npm

CVE-2025-69262

pnpm vulnerable to Command Injection via environment variable substitution

UNKNOWN
npm

CVE-2026-24131

pnpm has Path Traversal via arbitrary file permission modification

MEDIUM 6.5
npm

CVE-2026-23888

pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)

MEDIUM 6.5
npm

CVE-2026-24056

pnpm has symlink traversal in file:/git dependencies

MEDIUM 6.5
npm

CVE-2026-23890

pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin

MEDIUM 6.5
npm

CVE-2026-23889

pnpm has Windows-specific tarball Path Traversal

MEDIUM 6.5
npm

CVE-2024-47829

pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting

HIGH 7.5
npm

CVE-2023-37478

pnpm incorrectly parses tar archives relative to specification

HIGH 8.8
npm

CVE-2022-26183

Untrusted Search Path in PNPM

Learn What is SAST?

Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →

Ready to move

Start Securing

Free, no credit card | First findings in minutes