OCTOBER 9, 2026
Live Feed
Back to database
Case File

CVE-2026-101043

HIGH · CVSS 7.4 EPSS 0.22% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-27 · Last synced 2026-10-09

CyberRota Analysis

AI-Generated

Versions of pnpm prior to 11.11.0 and 10.34.5 are vulnerable to an environment variable expansion flaw in the httpProxy, httpsProxy, and noProxy settings, which can be exploited by an attacker controlling a repository's pnpm-workspace.yaml. This vulnerability allows the attacker to route installation traffic through a malicious host, potentially exfiltrating sensitive environment variables like NPM_TOKEN or GITHUB_TOKEN. Users of pnpm, particularly those managing repositories, should prioritize upgrading to the patched versions to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-101043
Severity
HIGH
CVSS
7.4
EPSS
0.22%
GitHub

Original NVD Description

pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-destination key set that otherwise suppresses placeholder expansion for untrusted manifests (as already done for registry, pnprServer, registries and namedRegistries), an attacker who controls a repository's pnpm-workspace.yaml can cause a victim who clones the repository and runs a pnpm command (e.g. pnpm install) to expand environment secrets such as NPM_TOKEN or GITHUB_TOKEN into a proxy hostname or userinfo and route install traffic — and the corresponding DNS lookups — through an attacker-controlled host. The exfiltration occurs during configuration loading, before any lifecycle script executes. Fixed in pnpm 11.11.0 and 10.34.5.