CVE-2025-69264Patch(pnpm / pnpm)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pnpm pnpm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDependencies mechanism, git dependencies can still execute prepare, prepublish, and prepack scripts during the fetch phase, enabling remote code execution without user consent or approval. This issue is fixed in version 10.26.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-13: 1Patch / Workaround · 2026-05-13: 1Technical Details · 2026-05-13: 105-13
Signal classification1 categories
Patch
1100.0%
Full discourse1 post
  • Oren Yomtov@orenyomtov
    Patch

    Fun fact: we implemented this config option as part of the mitigation for the script execution bypass vulnerability I disclosed to pnpm (CVE-2025-69264) https://t.co/Wo028yAiab

    Post summary

    The tweet announces that a mitigation configuration has been implemented for the script execution bypass vulnerability (CVE-2025-69264). No PoC, exploit code, or active exploitation is mentioned.

    110721.7K
    4.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm--node.js

Explore more