Environmental Variable Exposure in pnpm Package Manager
CVE-2026-55180
6.5MEDIUM
What is CVE-2026-55180?
The pnpm package manager contains a vulnerability where ENV_VAR placeholders in user-controlled configuration files can inadvertently expose environment secrets. This issue can be exploited by malicious repositories, allowing them to capture sensitive information intended for registry requests. Specifically, before the release of versions 10.34.2 and 11.5.3, these placeholders in .npmrc and pnpm-workspace.yaml could redirect environment details to an attacker-selected registry. Users are urged to update to the latest versions to mitigate this exposure.
Affected Version(s)
pnpm < 10.34.2 < 10.34.2
pnpm >= 11.0.0, < 11.5.3 < 11.0.0, 11.5.3
