CVE-2026-50573Disclosure(pnpm / pnpm)

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch pnpm pnpm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded tarball does not match the integrity recorded in pnpm-lock.yaml. When a package is already locked with an integrity value, and the registry later serves different metadata and tarball content for the same package name and version, pnpm initially reports an integrity mismatch. However, plain pnpm install then performs a resolution repair, accepts the registry's new integrity, updates the lockfile, installs the new content, and exits successfully. This means the lockfile integrity check does not act as a hard stop by default. This vulnerability is fixed in 10.34.0 and 11.4.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-25: 2Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 206-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-50573 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded ta… https://www.cve.org/CVERecord?id=CVE-2026-50573 ----- Traducción: CVE-2026-50573 pnp… http://infoflow.cloud`

    Post summary

    The tweet announces CVE‑2026‑50573, noting that pnpm prior to versions 10.34.0/11.4.0 can accept new remote package content in non‑frozen mode, and links to the CVE record, but provides no PoC, exploit, patch, or active exploitation details.

    0000042
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-50573 pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package content after detecting that the downloaded ta… https://www.cve.org/CVERecord?id=CVE-2026-50573

    Post summary

    CVE-2026-50573 affects pnpm before versions 10.34.0 and 11.4.0, allowing `pnpm install` in non‑frozen mode to accept newly downloaded package content; upgrade to patched releases to remediate.

    00000763
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more