CVE-2026-55700

HIGH CVSS 3.1: 7.1 EPSS 0.35%
Updated Jun 30, 2026
Pnpm
Parameter Value
CVSS 7.1 (HIGH)
Affected Versions 11.3.0 — 11.5.3
Fixed In 11.5.3
Type CWE-73 (External Control of File Name or Path), CWE-22 (Path Traversal)
Vendor Pnpm
Public PoC No

pnpm is a package manager. From 11.3.0 until 11.5.3, `pnpm stage download` derived a local filename from registry-controlled package name and version fields. A crafted manifest could escape the selected download directory and overwrite another reachable file.

The merged fix validates both fields, derives one safe filename, and verifies the final destination before writing. This vulnerability is fixed in 11.5.3.

Attack Parameters

Attack Vector
Network
Can be exploited remotely
Attack Complexity
Low
Easy to exploit
Privileges Required
None
No privileges needed
User Interaction
Required
User action required

Impact Assessment

Confidentiality
None
No data leak
Integrity
High
Complete data modification
Availability
Low
Partial disruption

CVSS Vector v3.1

Vulnerable Products 1

Configuration From (including) Up to (excluding)
Pnpm Pnpm
cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*
11.3.0 11.5.3