Known Vulnerabilities for Npm-lockfile by Npm-lockfile Project
Listed below are 1 of the newest known vulnerabilities associated with "Npm-lockfile" by "Npm-lockfile Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59196 json | pnpm is a package manager. Prior to 10.34.4 and 11.7.0, a crafted lockfile alias could be joined directly under a hoisted nod... | Not Provided | 2026-07-06 | 2026-07-06 |
| CVE-2026-59195 json | pnpm is a package manager. Prior to 10.34.4 and 11.8.0, pnpm accepts package names from the env lockfile configDependencies s... | Not Provided | 2026-07-06 | 2026-07-07 |
| CVE-2026-55698 json | pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-50573 json | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` in non-frozen mode can accept new remote package conte... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-50021 json | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm's tarball extraction worker skips integrity verification when th... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-50014 json | pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to gi... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-48995 json | pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it ... | Not Provided | 2026-06-25 | 2026-06-26 |
| CVE-2026-44628 json | An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE T... | Not Provided | 2026-06-30 | 2026-07-01 |
| CVE-2026-32148 json | Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency inte... | Not Provided | 2026-04-30 | 2026-05-01 |
| CVE-2025-69263 json | pnpm is a package manager. Versions 10.26.2 and below store HTTP tarball dependencies (and git-hosted tarballs) in the lockfi... | Not Provided | 2026-01-07 | 2026-07-15 |