Pnpm · Pnpm · CVE-2026-55180
**Name of the Vulnerable Software and Affected Versions**
pnpm versions prior to 10.34.2
pnpm versions prior to 11.5.3
pacquet (affected versions not specified)
**Description**
pnpm and pacquet expand `${ENV VAR}` placeholders from repository-controlled `.npmrc` and `pnpm-workspace.yaml` files into registry request destinations and registry credentials. A malicious repository can exploit this to force dependency resolution to send environment secrets from the victim's system to an attacker-controlled registry before lifecycle scripts are executed.
**Recommendations**
Update pnpm to version 10.34.2 or later.
Update pnpm to version 11.5.3 or later.
At the moment, there is no information about a newer version that contains a fix for this vulnerability for pacquet.