CVE-2026-55698Disclosure(pnpm / pnpm)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pnpm pnpm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env lockfile contained matching pnpm and @pnpm/exe versions. A malicious repository could therefore commit package-manager lockfile package records and snapshots that bypassed fresh package-manager resolution, then cause pnpm to install and execute bytes selected by that committed lockfile state during automatic version switching. This vulnerability is fixed in 10.34.2 and 11.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-345CWE-494CWE-829

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-06-25); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-06-25: 3Mentions · 2026-06-26: 1Patch / Workaround · 2026-06-25: 1Patch / Workaround · 2026-06-26: 1Technical Details · 2026-06-25: 2Technical Details · 2026-06-26: 106-2506-26
Signal classification1 categories
Disclosure
4100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-253
Disclosure3
2026-06-261
Disclosure1
Full discourse4 posts
  • Aretiq.AI@AretiqAI
    Disclosure

    ARETIQ Daily Vulnerability Bulletin — June 25, 2026 🔴 CRITICAL: CVE-2026-50016 (pnpm/pnpm) AAS 13.2 🔴 CRITICAL: CVE-2026-55698 (pnpm/pnpm) AAS 13.2 20 vulnerabilities — CRITICAL: 2, HIGH: 18 Full bulletin: https://aretiq.ai/bulletins/2026-06-25/

    Post summary

    The bulletin announces two critical vulnerabilities (CVE-2026-50016 and CVE-2026-55698) affecting pnpm/pnpm AAS 13.2, noting their severity but providing no exploitation, mitigation, or technical details.

    00010105
    191 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 HIGH - Lockfile bootstrap trust bypass leads to malicious pnpm execution (CVE-2026-55698) pnpm could persist bootstrap metadata in pnpm-lock.yaml and incorrectly trust an already resolved packageManagerDependencies entry when the committed lockfile matched the pnpm and @pnpm/exe versions. The root cause is improper trust of lockfile-resolved bootstrap metadata (integrity/validation failure) during automatic version switching, allowing attacker-controlled records and snapshots to short-circuit fresh package-manager resolution. An attacker exploits this by committing a crafted pnpm-lock.yaml into a malicious repository and relying on a victim running pnpm in that repo with auto-switching enabled, requiring no special privileges beyond getting the lockfile used. Impact is arbitrary code execution via installing and executing attacker-selected bytes, enabling full compromise of developer workstations and CI runners. 👉 Affected: pnpm <10.34.2 and 11.0.0-11.5.2 | Upgrade to 10.34.2 or 11.5.3

    Post summary

    The post announces a high-severity vulnerability in pnpm that allows arbitrary code execution via a tampered lockfile and recommends upgrading to patched versions.

    0000072
    231 followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-55698 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the p… https://www.cve.org/CVERecord?id=CVE-2026-55698 ----- Traducción: CVE-2026-55698 pnp… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-55698, noting that pnpm before versions 10.34.2 and 11.5.3 stores bootstrap metadata in the first YAML document of pnpm-lock.yaml.

    0000038
    89 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-55698 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the p… https://www.cve.org/CVERecord?id=CVE-2026-55698

    Post summary

    The post announces a vulnerability in pnpm’s lock file handling, states the affected versions, and references the patched releases.

    00000764
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more