PT-2026-99561 · Pnpm · Pnpm

CVE-2026-101043

·

Published

2026-09-01

·

Updated

2026-09-27

CVSS v4.0

8.3

High

VectorAV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions pnpm versions 11.0.0 through 11.10.f pnpm versions 10.7.0 through 10.34.4
Description The software expands ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml file. Since this manifest is repository-controlled, an attacker who controls the pnpm-workspace.yaml can force a user who clones the repository and executes a pnpm command to expand environment secrets, such as NPM TOKEN or GITHUB TOKEN, into a proxy hostname or userinfo. This allows the attacker to route installation traffic and DNS lookups through a host under their control. The exfiltration happens during configuration loading, before any lifecycle script is executed.
Recommendations Update pnpm to version 11.11.0. Update pnpm to version 10.34.5.

Exploit

Fix

Cleartext Transmission of Sensitive Information

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-101043
GHSA-VX52-2968-3VC6

Affected Products

Pnpm