CVE-2026-48995: pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
Summary
A malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile.
Details
The lockfile does not store the hash of the dependencies from https://codeload.github.com
This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies.
PoC
sh > pnpm -v 10.28.2
Given the following package.json:
json { "dependencies": { "add": "git://github.com/dsherret/npm-git-dep.git#b3eeb9b" } }
This produces a lockfile like so:
yaml lockfileVersion: '9.0'
settings: autoInstallPeers: true excludeLinksFromLockfile: false
importers:
.: dependencies: add: specifier: git://github.com/dsherret/npm-git-dep.git#b3eeb9b version: https://codeload.github.com/dsherret/npm-git-dep/tar.gz/b3eeb9b
packages:
add@https://codeload.github.com/dsherret/npm-git-dep/tar.gz/b3eeb9b: resolution: {tarball: https://codeload.github.com/dsherret/npm-git-dep/tar.gz/b3eeb9b} version: 1.0.0
snapshots:
add@https://codeload.github.com/dsherret/npm-git-dep/tar.gz/b3eeb9b: {}
Notice that there is no hash. The b3eeb9b is not sufficient because I can configure my machine to resolve a compromised tarball from that url (I tested it out and pnpm just installs it).
Impact
Anyone relying on github git dependencies.
Other sources
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash of the dependencies from https://codeload.github.com. This means that if this server was compromised or a person's machine configuration was compromised, pnpm would download and install these dependencies. This vulnerability is fixed in 10.33.4 and 11.0.7.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/pnpmto a version that resolves this vulnerability.Fixed in 11.0.7 - Upgrade
Upgrade
npm/pnpmto a version that resolves this vulnerability.Fixed in 10.33.4 - Upgrade
Upgrade
pnpmto a version that resolves this vulnerability.Fixed in 10.33.4 - Upgrade
Upgrade
pnpmto a version that resolves this vulnerability.Fixed in 11.0.7
Event History
Frequently Asked Questions
What is the severity of CVE-2026-48995?
CVE-2026-48995 has a medium severity rating with a CVSS score of 4.8.
How can I mitigate CVE-2026-48995?
To mitigate CVE-2026-48995, ensure that GitHub tarball dependencies are sourced from trusted origins and consider manually verifying package integrity.
What impact does CVE-2026-48995 have on pnpm?
CVE-2026-48995 allows a malicious server to deliver compromised tarballs for GitHub git dependencies, which could lead to the installation of malicious code.
When was CVE-2026-48995 published?
CVE-2026-48995 was published on June 25, 2026.
Which software is affected by CVE-2026-48995?
CVE-2026-48995 affects the pnpm package manager and its interaction with npm/pnpm dependencies.