CVE-2025-69264
pnpm Git Dependency Code Execution Vulnerability
Halo Surface Signal: 1 out of 5 — much less likely to be public-facing.
A vulnerability in the pnpm package manager allows git-hosted dependencies to execute arbitrary code during installation, bypassing security protections. This could enable unauthorized code execution on systems using affected versions. Confirmation of pnpm's use in your development or build processes is advised.