CVE-2026-55487Disclosure(pnpm / pnpm)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch pnpm pnpm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other opaque locators. Approval for one source string could therefore authorize a different attacker-controlled source whose locator normalized to the same value. This vulnerability is fixed in 10.34.2 and 11.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-346CWE-693CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-06-25: 3Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 306-25
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55487 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other op… https://www.cve.org/CVERecord?id=CVE-2026-55487 ----- Traducción: CVE-2026-55487 pnp… http://infoflow.cloud`

    Post summary

    The message announces CVE-2026-55487, noting that pnpm versions prior to 10.34.2 and 11.5.3 suffer from a normalizer issue that removes parenthesized text from various input sources.

    0001044
    89 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-55487 Peer-Suffix Normalizer Vulnerability in pnpm Before 10.34.2 and 11.5.3 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-55487

    Post summary

    The post announces the discovery of CVE‑2026‑55487—a Peer‑Suffix Normalizer vulnerability in pnpm versions before 10.34.2 and 11.5.3—without offering proofs, exploits, or mitigation details.

    00000129
    4.1K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55487 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, the generic peer-suffix normalizer also stripped parenthesized text from git, URL, tarball, file, and other op… https://www.cve.org/CVERecord?id=CVE-2026-55487

    Post summary

    The CVE describes a flaw in pnpm’s peer‑suffix normalizer affecting versions before 10.34.2 and 11.5.3, with the implied fix in those releases.

    00000785
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more