
CVE-2026-48995 pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious http://codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless… https://www.cve.org/CVERecord?id=CVE-2026-48995
Post summary
CVE-2026-48995 exposes pnpm's ability to accept unverified tarballs from a malicious codeload.github.com server prior to version 10.33.4 and 11.0.7.
