CVE-2026-48995: pnpm: Tarball hash of GitHub git dependencies is not stored in lockfile
A malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile.
References
Code Behaviors & Features
Detect and mitigate CVE-2026-48995 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →