VYPR
High severity7.5NVD Advisory· Published Jun 25, 2026· Updated Jun 30, 2026

CVE-2026-55697

CVE-2026-55697

Description

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependency and pnpm treated that repository-controlled dependency as an install-engine opt-in. During install, pnpm resolved a platform-specific @pacquet/-/pacquet binary from node_modules/.pnpm-config/ and spawned it as the developer or CI user. This vulnerability is fixed in 10.34.2 and 11.5.3.

Affected products

4
  • Pnpm/Pnpminferred3 versions
    (expand)+ 2 more
    • (no CPE)
    • cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*range: <10.34.2
    • (no CPE)range: <10.34.2, <11.5.3
  • ghsa-coords
    Range: < 10.34.2

Patches

Vulnerability mechanics

References

3

News mentions

1