pnpm: Repository-controlled configDependencies can select a pacquet native install engine
Published Jun 25, 2026
8.8
HIGHCVSS 3.1
EPSS 0.19%
Description
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacquet or @pnpm/pacquet as a config dependency and pnpm treated that repository-controlled dependency as an install-engine opt-in. During install, pnpm resolved a platform-specific @pacquet/<platform>-<arch>/pacquet binary from node_modules/.pnpm-config/<packageName> and spawned it as the developer or CI user. This vulnerability is fixed in 10.34.2 and 11.5.3.
Affected products
-
- Version < 10.34.2StatusaffectedConstraints-
- Version >= 11.0.0, < 11.5.3StatusaffectedConstraints-
- Version
No data.
Red Hat AMQ Broker 7
pnpm
Not affected
Red Hat Build of Keycloak
pnpm
Not affected
Red Hat JBoss Enterprise Application Platform 8
pnpm
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
pnpm
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat AMQ Broker 7 | pnpm | Not affected | n/a |
| Red Hat Build of Keycloak | pnpm | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform 8 | pnpm | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | pnpm | Not affected | n/a |
pnpm
npm
Introduced 0 Fixed 10.34.2pnpm
npm
Introduced 11.0.0 Fixed 11.5.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | pnpm | 0 | 10.34.2 |
| npm | pnpm | 11.0.0 | 11.5.3 |
Remediation
Red Hat statement
This is an Important arbitrary code execution flaw in pnpm, a package manager. A remote attacker could exploit this by crafting a malicious repository that, when used by a developer or CI system, leads to the execution of a malicious binary. This vulnerability arises from pnpm's improper handling of `configDependencies` declared in `pnpm-workspace.yaml`, allowing an untrusted repository to opt into a native install engine.
References (6)
- https://access.redhat.com/security/cve/CVE-2026-55697 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2493038 Issue Tracking
- https://github.com/advisories/GHSA-gj8w-mvpf-x27x Advisory
- https://github.com/pnpm/pnpm/security/advisories/GHSA-gj8w-mvpf-x27x exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-55697
- https://www.cve.org/CVERecord?id=CVE-2026-55697
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2026-55697 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2493038 | Issue Tracking | |
| https://github.com/advisories/GHSA-gj8w-mvpf-x27x | Advisory | |
| https://github.com/pnpm/pnpm/security/advisories/GHSA-gj8w-mvpf-x27x | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2026-55697 | ||
| https://www.cve.org/CVERecord?id=CVE-2026-55697 |
Change history (0)
No recorded changes yet.