CVE-2026-50014Disclosure(pnpm / pnpm)

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a malicious lockfile can replace the expected 40-character commit hash with a Git option such as --upload-pack=<command>. For SSH and local transports, --upload-pack can execute the supplied command. HTTPS transports ignore --upload-pack, so the practical attack surface is primarily SSH or local git dependencies. This vulnerability is fixed in 10.34.0 and 11.4.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-27: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-27: 106-2506-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-06-271
Disclosure1
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50014 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-… https://www.cve.org/CVERecord?id=CVE-2026-50014 ----- Traducción: CVE-2026-50014 pnp… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-50014, a flaw in pnpm where a commit value is incorrectly passed to git fetch, but does not provide evidence of exploitation or a patch.

    0001037
    89 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 pnpm (npm/pnpm), Argument Injection, #CVE-2026-50014 (Critical) -DC-Jun2026-718 https://dailycve.com/pnpm-npm-pnpm-argument-injection-cve-2026-50014-critical-dc-jun2026-718/

    Post summary

    A critical Argument Injection vulnerability (CVE‑2026‑50014) was disclosed, with no PoC, exploit tools, or patches referenced.

    0000047
    216 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50014 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-… https://www.cve.org/CVERecord?id=CVE-2026-50014

    Post summary

    The tweet merely reports that CVE‑2026‑50014 is a vulnerability affecting pnpm prior to versions 10.34.0 and 11.4.0, with no evidence of exploitation or available fixes.

    00000677
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more