Package Manager Vulnerability in pnpm Affecting Various Versions
CVE-2025-69263
7.5HIGH
What is CVE-2025-69263?
The pnpm package manager contains a significant vulnerability where HTTP tarball dependencies and git-hosted tarballs can be stored in the lockfile without proper integrity hashes in versions up to 10.26.2. This flaw allows an attacker to provide different code to users or CI/CD environments, as the lockfile does not prevent a remote server from serving altered content upon each installation. To mitigate this risk, users are advised to upgrade to version 10.26.0 or later, which addresses this issue.
Affected Version(s)
pnpm < 10.26.0
