Back

HIGH

pnpm Lockfile Integrity Bypass Allows Remote Dynamic Dependencies

Published Jan 7, 2026

Description

pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfile without integrity hashes. This allows the remote server to serve different content on each install, even when a lockfile is committed. An attacker who publishes a package with an HTTP tarball dependency can serve different code to different users or CI/CD environments. The attack requires the victim to install a package that has an HTTP/git tarball in its dependency tree. The victim's lockfile provides no protection. This issue is fixed in version 10.26.0.

Affected products

Remediation

Red Hat mitigation

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Weaknesses (1)

References (9)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner GitHub_M
Published Jan 7, 2026
Updated Sep 14, 2026
Reserved Dec 30, 2025
CISA Vulnrichment
Updated Jan 9, 2026
NVD
Status Modified
Modified Jul 15, 2026
Red Hat
Severity Important
Public date Jan 7, 2026
ENISA EUVD
Assigner GitHub_M
Published Jan 7, 2026
Updated Sep 14, 2026
Exploited since n/a
EUVD-2026-1190 GHSA-7VHP-VF5G-R2FW