Executive brief
pnpm is a popular JavaScript package manager that supports build approval policies for third-party dependencies. This vulnerability allows attackers to bypass build approval controls by spoofing package identities—an attacker can get approval for one package source and then run builds from a different attacker-controlled source. An exploit requires user interaction (manually approving a build) but could lead to arbitrary code execution during package installation.
Technical details
The vulnerability exists in pnpm's build approval policy implementation. The affected code applies generic peer-suffix normalization (stripping parenthesized text) to both registry and opaque (git, URL, tarball, file, directory) dependency locators. This normalization allows different source strings to collide: for example, both `foo@https://host/pkg.tgz` and `foo@https://host/pkg.tgz(evil)` normalize to the same value after parenthesized text is removed, allowing an attacker to construct a malicious locator that matches an approved source. The vulnerability class is CWE-346 (Origin Validation Error) and requires user interaction to approve a build. The patch (versions 10.34.2 and 11.5.3+) enforces byte-exact matching for opaque identities while retaining normalized matching for legitimate registry packages, preventing collision-based spoofing.
Affected products
- pnpm pnpm <10.34.2, >=11.0.0 <11.5.3
Timeline
- 2026-06-26: disclosed: GHSA-5wx6-mg75-v57r published on OSV
- 2026-06-10: patched: Patch commit bf1b731ee6 merged to fix the original name-only approval bypass
- 2026-06-26: other: Final patch released in pnpm v10.34.2 and v11.5.3 addressing all three collision forms