Medium severity6.8NVD Advisory· Published Jun 25, 2026· Updated Jun 29, 2026
CVE-2026-50021
CVE-2026-50021
Description
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when the integrity field is absent from the lockfile resolution. If an attacker can both modify pnpm-lock.yaml to remove the integrity: field and cause the referenced registry URL to serve altered package content, pnpm install --frozen-lockfile can install the altered package without an integrity error. npm's npm ci enforces integrity by default; pnpm's behavior of silently skipping verification is a pnpm-specific fail-open gap. This vulnerability is fixed in 10.34.0 and 11.4.0.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
pnpmnpm | >= 11.0.0, < 11.4.0 | 11.4.0 |
pnpmnpm | < 10.34.1 | 10.34.1 |
Affected products
2Patches
Vulnerability mechanics
References
3- github.com/pnpm/pnpm/security/advisories/GHSA-q6j5-fjx5-2mc3nvdExploitMitigationVendor AdvisoryWEB
- github.com/advisories/GHSA-q6j5-fjx5-2mc3ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-50021ghsaADVISORY
News mentions
1- Pnpm: Thirteen Vulnerabilities Disclosed Together, Posing Risks of ACE and Supply Chain CompromiseVypr Intelligence · Jun 25, 2026