CVE-2026-101043: pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings
pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-destination key set that otherwise suppresses placeholder expansion for untrusted manifests (as already done for registry, pnprServer, registries and namedRegistries), an attacker who controls a repository's pnpm-workspace.yaml can cause a victim who clones the repository and runs a pnpm command (e.g. pnpm install) to expand environment secrets such as NPMTOKEN or GITHUBTOKEN into a proxy hostname or userinfo and route install traffic — and the corresponding DNS lookups — through an attacker-controlled host. The exfiltration occurs during configuration loading, before any lifecycle script executes. Fixed in pnpm 11.11.0 and 10.34.5.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
pnpmto a version that resolves this vulnerability.Fixed in 11.11.0 - Upgrade
Upgrade
pnpmto a version that resolves this vulnerability.Fixed in 10.34.5
Event History
Frequently Asked Questions
Which users and workflows are exposed?
Users of pnpm 11.0.0 through before 11.11.0, or 10.7.0 through before 10.34.5, are exposed when they run a pnpm command against a repository containing an attacker-controlled pnpm-workspace.yaml. A clone followed by a command such as pnpm install is sufficient.
Does exploitation require lifecycle scripts or prior access to the victim machine?
No lifecycle script execution is required. The malicious proxy configuration is processed during configuration loading, before lifecycle scripts run; the attacker needs control of the repository's pnpm-workspace.yaml and relies on the victim running pnpm.
What information can be exposed?
Environment-variable values referenced in httpProxy, httpsProxy, or noProxy placeholders can be incorporated into an attacker-controlled proxy hostname or userinfo. The advisory specifically identifies secrets such as NPM_TOKEN and GITHUB_TOKEN, with install traffic and associated DNS lookups routed through the attacker-controlled host.
What should be done if an affected version cannot be upgraded immediately?
Do not run pnpm commands in untrusted or newly cloned repositories until their pnpm-workspace.yaml has been reviewed for httpProxy, httpsProxy, and noProxy settings containing ${VAR} placeholders. Upgrading to pnpm 11.11.0 or 10.34.5 resolves the issue.
How can teams determine whether they may already be affected?
Check whether affected pnpm versions were used on repositories whose pnpm-workspace.yaml set httpProxy, httpsProxy, or noProxy with environment-variable placeholders. Review for unexpected proxy routing or DNS lookups occurring when pnpm commands were run, especially where sensitive environment variables such as NPM_TOKEN or GITHUB_TOKEN were present.