Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

redhat логотип

CVE-2025-69262

7 месяцев назад

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

CVSS3: 7.5
EPSS: Низкий
nvd логотип

CVE-2025-69262

7 месяцев назад

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-69262

7 месяцев назад

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Comm ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phv-j68v-wwqx

7 месяцев назад

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
nvd логотип
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

CVSS3: 7.5
1%
Низкий
7 месяцев назад
debian логотип
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Comm ...

CVSS3: 7.5
1%
Низкий
7 месяцев назад
github логотип
GHSA-2phv-j68v-wwqx

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
1%
Низкий
7 месяцев назад

Уязвимостей на страницу