Dependency scanning
Check whether pnpm is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
CVE-2026-55697
pnpm: Repository-controlled configDependencies can select a pacquet native install engine
CVE-2026-59196
pnpm: Hoisted install imports lockfile alias outside node_modules
CVE-2026-59194
pnpm: `patch-remove` could delete project-selected files outside the patches directory
CVE-2026-59195
pnpm: Path traversal in configDependencies env lockfile allows symlink creation outside node_modules/.pnpm-config
CVE-2026-55700
pnpm: `stage download` writes outside its destination directory via manifest name/version traversal
CVE-2026-55699
pnpm: Reserved bin name deletes PNPM_HOME during global remove
CVE-2026-55698
pnpm: Project env lockfile can short-circuit package-manager resolution and execute lockfile-selected pnpm bytes
CVE-2026-55487
pnpm: Manifest identity spoof satisfies allowBuilds and runs attacker lifecycle
CVE-2026-55180
pnpm: Repository config can expand victim environment secrets into registry requests before scripts run
CVE-2026-50015
pnpm Vulnerable to Arbitrary File Write/Delete via Malicious Patch File (Path Traversal)
CVE-2026-50017
pnpm binds unscoped user-level npm auth credentials to a repository-selected registry
CVE-2026-50573
pnpm: Unsafe default behavior breaks integrity check
CVE-2026-50014
pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
CVE-2026-50016
pnpm: Transitive dependency alias path traversal allows project path override via symlink replacement
CVE-2026-50021
pnpm Has an Integrity Check Bypass via Missing Lockfile Integrity Field
CVE-2026-48995
pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
CVE-2024-53866
pnpm no-script global cache poisoning via overrides / `ignore-scripts` evasion
CVE-2025-69263
pnpm Has Lockfile Integrity Bypass that Allows Remote Dynamic Dependencies
CVE-2025-69264
pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
CVE-2025-69262
pnpm vulnerable to Command Injection via environment variable substitution
CVE-2026-24131
pnpm has Path Traversal via arbitrary file permission modification
CVE-2026-23888
pnpm: Binary ZIP extraction allows arbitrary file write via path traversal (Zip Slip)
CVE-2026-24056
pnpm has symlink traversal in file:/git dependencies
CVE-2026-23890
pnpm scoped bin name Path Traversal allows arbitrary file creation outside node_modules/.bin
CVE-2026-23889
pnpm has Windows-specific tarball Path Traversal
CVE-2024-47829
pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
CVE-2023-37478
pnpm incorrectly parses tar archives relative to specification
CVE-2022-26183
Untrusted Search Path in PNPM
Browse more npm advisories
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes