Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-12168 | pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0. |
Github GHSA |
GHSA-8cc4-rfj6-fhg4 | pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting |
Fri, 19 Sep 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:*:node.js:* |
Fri, 25 Apr 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Thu, 24 Apr 2025 08:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 23 Apr 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | pnpm is a package manager. Prior to version 10.0.0, the path shortening function uses the md5 function as a path shortening compression function, and if a collision occurs, it will result in the same storage path for two different libraries. Although the real names are under the package name /node_modoules/, there are no version numbers for the libraries they refer to. This issue has been patched in version 10.0.0. | |
| Title | pnpm uses the md5 path shortening function causes packet paths to coincide, which causes indirect packet overwriting | |
| Weaknesses | CWE-328 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-04-23T16:08:45.843Z
Reserved: 2024-10-03T14:06:12.642Z
Link: CVE-2024-47829
Updated: 2025-04-23T16:08:32.391Z
Status : Analyzed
Published: 2025-04-23T16:15:29.910
Modified: 2025-09-19T20:08:55.927
Link: CVE-2024-47829
OpenCVE Enrichment
Updated: 2025-07-13T11:31:17Z
EUVD
Github GHSA