CVE-2024-47829
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/04/2025
Last modified:
19/09/2025
Description
pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:*:node.js:* | 10.0.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



