CVE 7.6 HIGH

pnpm vulnerable to Command Injection via environment variable substitution_CVE-2025-69262

7.6 / 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

Description

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

Basic Information

ID CVE-2025-69262
Source GitHub_M
Published Jan 7, 2026 at 22:30

Affected Product

Vendor pnpm
Product pnpm
Version >=6.25.0, < 10.27.0
Affected Versions pnpm pnpm >=6.25.0, < 10.27.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.