Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55180

Опубликовано: 25 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository could cause dependency resolution to send victim environment secrets to an attacker-selected registry before lifecycle scripts run. This vulnerability is fixed in 10.34.2 and 11.5.3.

A flaw was found in pnpm and pacquet. A malicious repository could exploit this vulnerability by crafting specific .npmrc or pnpm-workspace.yaml files. When these package managers process these files, they improperly expand environment variable placeholders, leading to the disclosure of sensitive victim environment secrets to an attacker-controlled registry. This could result in unauthorized access to confidential information.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat AMQ Broker 7pnpmFix deferred
Red Hat Build of KeycloakpnpmFix deferred
Red Hat JBoss Enterprise Application Platform 8pnpmFix deferred
Red Hat JBoss Enterprise Application Platform Expansion PackpnpmFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-15
https://bugzilla.redhat.com/show_bug.cgi?id=2493031pnpm: pacquet: pnpm and pacquet: Information disclosure of environment secrets via improper environment variable expansion

EPSS

Процентиль: 25%
0.00326
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
nvd
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository could cause dependency resolution to send victim environment secrets to an attacker-selected registry before lifecycle scripts run. This vulnerability is fixed in 10.34.2 and 11.5.3.

CVSS3: 6.5
debian
около 1 месяца назад

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacqu ...

CVSS3: 6.5
github
около 1 месяца назад

pnpm: Repository config can expand victim environment secrets into registry requests before scripts run

EPSS

Процентиль: 25%
0.00326
Низкий

6.5 Medium

CVSS3