PT-2026-99561 · Pnpm · Pnpm
CVE-2026-101043
·
Published
2026-09-01
·
Updated
2026-09-27
CVSS v4.0
8.3
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
pnpm versions 11.0.0 through 11.10.f
pnpm versions 10.7.0 through 10.34.4
Description
The software expands
${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml file. Since this manifest is repository-controlled, an attacker who controls the pnpm-workspace.yaml can force a user who clones the repository and executes a pnpm command to expand environment secrets, such as NPM TOKEN or GITHUB TOKEN, into a proxy hostname or userinfo. This allows the attacker to route installation traffic and DNS lookups through a host under their control. The exfiltration happens during configuration loading, before any lifecycle script is executed.Recommendations
Update pnpm to version 11.11.0.
Update pnpm to version 10.34.5.
Exploit
Fix
Cleartext Transmission of Sensitive Information
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pnpm