Логотип exploitDog
bind:CVE-2025-69262
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-69262

Количество 3

Количество 3

nvd логотип

CVE-2025-69262

около 1 месяца назад

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

CVSS3: 7.5
EPSS: Низкий
debian логотип

CVE-2025-69262

около 1 месяца назад

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Comm ...

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-2phv-j68v-wwqx

около 1 месяца назад

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
debian логотип
CVE-2025-69262

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Comm ...

CVSS3: 7.5
0%
Низкий
около 1 месяца назад
github логотип
GHSA-2phv-j68v-wwqx

pnpm vulnerable to Command Injection via environment variable substitution

CVSS3: 7.5
0%
Низкий
около 1 месяца назад

Уязвимостей на страницу