Fast, disk space efficient package manager
97%
Total Score
100
100
91
100
100
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-789279 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. pnpm is vulnerable to Path Traversal in versions 6.25.0 - 10.34.4 and 11.0.0 - 11.10.0. | 6.25.0 - 10.34.411.0.0 - 11.10.0 | High |
CVE-2026-50015 pnpm is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 0.0.0 - 10.34.0 and 11.0.0 - 11.4.0. | 0.0.0 - 10.34.011.0.0 - 11.4.0 | High |
CVE-2026-50017 pnpm is vulnerable to Exposure of Sensitive Information to an Unauthorized Actor in versions 0.0.0 - 10.34.0 and 11.0.0 - 11.4.0. | 0.0.0 - 10.34.011.0.0 - 11.4.0 | Medium |
CVE-2026-50016 pnpm is vulnerable to Relative Path Traversal in versions 0.0.0 - 10.34.0 and 11.0.0 - 11.4.0. | 0.0.0 - 10.34.011.0.0 - 11.4.0 | High |
CVE-2026-50014 pnpm is vulnerable to Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') in versions 0.0.0 - 10.34.0 and 11.0.0 - 11.4.0. | 0.0.0 - 10.34.011.0.0 - 11.4.0 | Medium |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant