Environmental Variable Exposure in pnpm Package Manager
CVE-2026-55180

6.5MEDIUM

Key Information:

Vendor

Pnpm

Status
Vendor
CVE Published:
25 June 2026

What is CVE-2026-55180?

The pnpm package manager contains a vulnerability where ENV_VAR placeholders in user-controlled configuration files can inadvertently expose environment secrets. This issue can be exploited by malicious repositories, allowing them to capture sensitive information intended for registry requests. Specifically, before the release of versions 10.34.2 and 11.5.3, these placeholders in .npmrc and pnpm-workspace.yaml could redirect environment details to an attacker-selected registry. Users are urged to update to the latest versions to mitigate this exposure.

Affected Version(s)

pnpm < 10.34.2 < 10.34.2

pnpm >= 11.0.0, < 11.5.3 < 11.0.0, 11.5.3

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.