pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.
History

Fri, 25 Apr 2025 02:00:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Moderate


Thu, 24 Apr 2025 08:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 23 Apr 2025 16:00:00 +0000

Type Values Removed Values Added
Description pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0.
Title pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting
Weaknesses CWE-328
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-04-23T15:42:12.623Z

Updated: 2025-04-23T16:08:45.843Z

Reserved: 2024-10-03T14:06:12.642Z

Link: CVE-2024-47829

cve-icon Vulnrichment

Updated: 2025-04-23T16:08:32.391Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-04-23T16:15:29.910

Modified: 2025-04-29T13:52:47.470

Link: CVE-2024-47829

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-04-23T15:42:12Z

Links: CVE-2024-47829 - Bugzilla