CVE-2026-50021Disclosure(pnpm / pnpm)

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolution. If an attacker can both modify pnpm-lock.yaml to remove the integrity: field and cause the referenced registry URL to serve altered package content, pnpm install --frozen-lockfile can install the altered package without an integrity error. npm's npm ci enforces integrity by default; pnpm's behavior of silently skipping verification is a pnpm-specific fail-open gap. This vulnerability is fixed in 10.34.0 and 11.4.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-354

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-06-25); latest day: 1
  • 3 total mentions across 2 days

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-27: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-27: 106-2506-27
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-252
Disclosure2
2026-06-271
Disclosure1
Full discourse3 posts
  • DailyCVE@dailycve
    Disclosure

    🔴 pnpm (Package Manager), Integrity Check Bypass, #CVE-2026-50021 (High) -DC-Jun2026-711 https://dailycve.com/pnpm-package-manager-integrity-check-bypass-cve-2026-50021-high-dc-jun2026-711/

    Post summary

    A high‑severity integrity check bypass vulnerability (CVE‑2026‑50021) in the pnpm package manager has been disclosed, with no PoC, exploit, or patch details included in this brief.

    0001049
    216 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50021 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lock… https://www.cve.org/CVERecord?id=CVE-2026-50021 ----- Traducción: CVE-2026-50021 pnp… http://infoflow.cloud`

    Post summary

    The statement announces CVE‑2026‑50021 by describing its impact on pnpm tarball extraction and the conditions for the vulnerability, but provides no PoC, exploit code, or patch details.

    0000037
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50021 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lock… https://www.cve.org/CVERecord?id=CVE-2026-50021

    Post summary

    The post discloses CVE-2026-50021 affecting pnpm’s integrity checks, but offers no exploit or patch details.

    00000729
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more