Medium severity6.4NVD Advisory· Published Jun 25, 2026· Updated Jun 29, 2026
CVE-2026-50014
CVE-2026-50014
Description
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a malicious lockfile can replace the expected 40-character commit hash with a Git option such as --upload-pack=. For SSH and local transports, --upload-pack can execute the supplied command. HTTPS transports ignore --upload-pack, so the practical attack surface is primarily SSH or local git dependencies. This vulnerability is fixed in 10.34.0 and 11.4.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pnpmnpm | < 10.34.0 | 10.34.0 |
pnpmnpm | >= 11.0.0, < 11.4.0 | 11.4.0 |
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/pnpm/pnpm/security/advisories/GHSA-p4xf-rf54-rj3xnvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-p4xf-rf54-rj3xghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-50014ghsaADVISORY
News mentions
1- Pnpm: Thirteen Vulnerabilities Disclosed Together, Posing Risks of ACE and Supply Chain CompromiseVypr Intelligence · Jun 25, 2026