CVE-2025-69262

HIGH

pnpm 6.25.0-10.26.2 - Remote Code Execution via .npmrc Environment Variable Substitution

Title source: llm
STIX 2.1

Description

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

References (2)

Core 2
Core References
Exploit, Vendor Advisory x_refsource_confirm
https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx
Product, Release Notes x_refsource_misc
https://github.com/pnpm/pnpm/releases/tag/v10.27.0

Scores

CVSS v3 7.5
EPSS 0.0008
EPSS Percentile 23.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact total

Details

CWE
CWE-78 CWE-94
Status published
Products (2)
npm/pnpm 6.25.0 - 10.27.0npm
pnpm/pnpm 6.25.0 - 10.27.0
Published Jan 07, 2026
Tracked Since Feb 18, 2026