Package Manager Vulnerability in pnpm Affecting Various Versions
CVE-2025-69263

7.5HIGH

Key Information:

Vendor

Pnpm

Status
Vendor
CVE Published:
7 January 2026

What is CVE-2025-69263?

The pnpm package manager contains a significant vulnerability where HTTP tarball dependencies and git-hosted tarballs can be stored in the lockfile without proper integrity hashes in versions up to 10.26.2. This flaw allows an attacker to provide different code to users or CI/CD environments, as the lockfile does not prevent a remote server from serving altered content upon each installation. To mitigate this risk, users are advised to upgrade to version 10.26.0 or later, which addresses this issue.

Affected Version(s)

pnpm < 10.26.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.