The vendor explicitly states that these products are not affected by this CVE.
- pnpm as a component of Red Hat AMQ Broker 7
- pnpm as a component of Red Hat Build of Keycloak
- pnpm as a component of Red Hat JBoss Enterprise Application Platform 8
- pnpm as a component of Red Hat JBoss Enterprise Application Platform Expansion Pack
- Summary
- A flaw was found in pnpm, a package manager. This vulnerability allows a remote attacker to achieve arbitrary code execution by committing a specially crafted package-manager lockfile (`pnpm-lock.yaml`) to a repository. When pnpm is executed, it trusts an already resolved `packageManagerDependencies` entry, enabling the malicious lockfile to bypass standard package resolution. This can cause pnpm to install and execute attacker-controlled code during automatic version switching.
- Remediation
- No remediation text is recorded.
