GHSA-379q-355j-w6rj · Severity: high · Ecosystem: npm — pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
pnpm is a package manager. Versions 10.0.0 through 10.25 allow git-hosted dependencies to execute arbitrary code during pnpm install, circumventing the v10 security feature "Dependency lifecycle scripts execution disabled by default". While pnpm v10 blocks postinstall scripts via the onlyBuiltDependencies mechanism, git dependencies can still execute prepare, prepublish, and prepack scripts during the fetch phase, enabling remote code execution without user consent or approval. This issue is fixed in version 10.26.0.
Conclusion & alert: CVE-2025-69264 is rated Exploit Available (59.7/100): CVSS High severity, with low exploitation likelihood (EPSS 0.10%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-05 | 0.17% | 0.10% | -0.07% |
| 2 | 2026-05-09 | 0.11% | 0.17% | +0.06% |
| 3 | 2026-02-18 | — | 0.11% | — |
Full EPSS history (4 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 8.8 | 3.1 | HIGH |
|
2.8 | 5.9 | [email protected] |
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-379q-355j-w6rj · Severity: high · Ecosystem: npm — pnpm v10+ Bypass "Dependency lifecycle scripts execution disabled by default"
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2025-69264: 1 source package rows (pnpm); 26 state rows across 2 repos (3.23-community, edge-community); fixed 0, open 26. | https://security.alpinelinux.org/vuln/CVE-2025-69264 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-69264 |
| URL | Tags |
|---|---|
| https://github.com/pnpm/pnpm/commit/73cc63504d9bc360c43e4b2feb9080677f03c5b5 | Patch |
| https://github.com/pnpm/pnpm/security/advisories/GHSA-379q-355j-w6rj | Exploit Vendor Advisory |