CVE-2024-47829

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 23, 2025
Updated: Apr 29, 2025
CWE ID 328

Summary

CVE-2024-47829 is a vulnerability affecting the package manager pnpm. Before version 10.0.0, the path shortening function employed the md5 function as a compression tool for path shortening, leading to collisions where two distinct libraries could result in identical storage paths. Despite their different names, these libraries do not have version numbers specified in the package directory, making it challenging to distinguish between them. This issue has been rectified in version 10.0.0 of pnpm.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share