Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-55180

MEDIUM NVD
CVSS Score 6.5
Severity MEDIUM
Published Jun 25, 2026
Vendor unknown

Description

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository could cause dependency resolution to send victim environment secrets to an attacker-selected registry before lifecycle scripts run. This vulnerability is fixed in 10.34.2 and 11.5.3.

References