CVE-2026-55180

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository could cause dependency resolution to send victim environment secrets to an attacker-selected registry before lifecycle scripts run. This vulnerability is fixed in 10.34.2 and 11.5.3.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*
cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*

History

29 Jun 2026, 21:16

Type Values Removed Values Added
First Time Pnpm
Pnpm pnpm
CPE cpe:2.3:a:pnpm:pnpm:*:*:*:*:*:node.js:*:*
References () https://github.com/pnpm/pnpm/security/advisories/GHSA-3qhv-2rgh-x77r - () https://github.com/pnpm/pnpm/security/advisories/GHSA-3qhv-2rgh-x77r - Exploit, Vendor Advisory

25 Jun 2026, 19:16

Type Values Removed Values Added
References () https://github.com/pnpm/pnpm/security/advisories/GHSA-3qhv-2rgh-x77r - () https://github.com/pnpm/pnpm/security/advisories/GHSA-3qhv-2rgh-x77r -

25 Jun 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-25 18:16

Updated : 2026-06-29 21:16


NVD link : CVE-2026-55180

Mitre link : CVE-2026-55180

CVE.ORG link : CVE-2026-55180


JSON object : View

Products Affected

pnpm

  • pnpm
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

CWE-201

Insertion of Sensitive Information Into Sent Data

CWE-522

Insufficiently Protected Credentials