CVE-2026-50014: pnpm: Git Fetch Argument Injection via Lockfile resolution.commit
Summary
pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a malicious lockfile can replace the expected 40-character commit hash with a Git option such as --upload-pack=<command>. For SSH and local transports, --upload-pack can execute the supplied command. HTTPS transports ignore --upload-pack, so the practical attack surface is primarily SSH or local git dependencies.
Vulnerability Details
The vulnerable path is in fetching/git-fetcher/src/index.ts. When a git dependency host is configured for shallow fetching, pnpm calls:
typescript await execGit(['fetch', '--depth', '1', 'origin', resolution.commit], { cwd: tempLocation })
Because resolution.commit is appended before a -- separator, Git can parse a commit value beginning with - as an option. The same file later passes the value to git checkout without a separator:
typescript await execGit(['checkout', resolution.commit], { cwd: tempLocation })
resolution.commit comes from the lockfile and is typed as a plain string; pnpm does not validate it as a 40-character hexadecimal commit before passing it to Git.
Proof of Concept
bash bash autofynaudit/exploits/vuln11gituploadpackrce/exploit.sh Creates a local bare git repo and triggers the shallow-fetch path. Replaces the lockfile commit hash with '--upload-pack=touch /tmp/vuln11pwned'. Result: PASS -- /tmp/vuln11pwned created by injected touch command.
The PoC uses a local file://githost/... repository because the injection requires a local or SSH transport. HTTPS transport ignores --upload-pack.
Impact
Code execution as the user running pnpm install, under specific transport conditions. The attacker must modify pnpm-lock.yaml, and the affected dependency must use SSH or local git transport. HTTPS transport (the common case) is immune.
Suggested Remediation
Add a -- separator before lockfile-controlled git revision values. Validate resolution.commit matches /^[0-9a-f]{40}$/i before passing to Git.
---
> Discovered by AutoFyn > Full audit report: auditreport.md > Exploit script: exploit.sh
Other sources
pnpm is a package manager. Prior to 10.34.0 and 11.4.0, pnpm passes the lockfile-controlled git resolution.commit value to git fetch without a -- separator or commit-format validation. For git dependencies fetched through the shallow-fetch path, a malicious lockfile can replace the expected 40-character commit hash with a Git option such as --upload-pack=<command>. For SSH and local transports, --upload-pack can execute the supplied command. HTTPS transports ignore --upload-pack, so the practical attack surface is primarily SSH or local git dependencies. This vulnerability is fixed in 10.34.0 and 11.4.0.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/pnpmto a version that resolves this vulnerability.Fixed in 11.4.0 - Upgrade
Upgrade
npm/pnpmto a version that resolves this vulnerability.Fixed in 10.34.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.34.0 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 11.4.0 - Configuration
Validate `resolution.commit` from `pnpm-lock.yaml` matches `/^[0-9a-f]{40}$/i` before passing it to Git. This prevents injection via option-like values (e.g., `--upload-pack=...`) when pnpm performs `git fetch`/`git checkout`.
pnpm (git-fetcher; fetching/git-fetcher/src/index.ts) resolution.commit validation = Match /^[0-9a-f]{40}$/i before passing to Git - Configuration
Add a `--` separator before lockfile-controlled git revision values so Git cannot parse a commit value beginning with `-` as an option (fix applies to the value appended prior to `--` and should also be used for both the `git fetch` and the later `git checkout` argument construction paths).
pnpm (git fetch/checkout argument construction) git argument separator = Insert `--` separator before lockfile-controlled git revision values
Event History
Frequently Asked Questions
What is the severity of CVE-2026-50014?
The severity of CVE-2026-50014 is medium with a score of 6.4.
How do I fix CVE-2026-50014?
To fix CVE-2026-50014, upgrade pnpm to version 10.34.0 or 11.4.0 or later.
What type of vulnerability is CVE-2026-50014?
CVE-2026-50014 is an argument injection vulnerability related to git fetch via lockfile resolution in pnpm.
What software is affected by CVE-2026-50014?
The software affected by CVE-2026-50014 is pnpm.
What is the risk associated with CVE-2026-50014?
CVE-2026-50014 has a risk rating of 48.