{"id":"CVE-2026-101043","summary":"pnpm 11.0.0 before 11.11.0 Environment Variable Exfiltration via Proxy Settings","details":"pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-destination key set that otherwise suppresses placeholder expansion for untrusted manifests (as already done for registry, pnprServer, registries and namedRegistries), an attacker who controls a repository's pnpm-workspace.yaml can cause a victim who clones the repository and runs a pnpm command (e.g. pnpm install) to expand environment secrets such as NPM_TOKEN or GITHUB_TOKEN into a proxy hostname or userinfo and route install traffic — and the corresponding DNS lookups — through an attacker-controlled host. The exfiltration occurs during configuration loading, before any lifecycle script executes. Fixed in pnpm 11.11.0 and 10.34.5.","aliases":["GHSA-vx52-2968-3vc6"],"modified":"2026-09-28T03:48:38.028014549Z","published":"2026-09-27T17:02:33.119Z","database_specific":{"cwe_ids":["CWE-201"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101043.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/101xxx/CVE-2026-101043.json"},{"type":"ADVISORY","url":"https://github.com/pnpm/pnpm/security/advisories/GHSA-vx52-2968-3vc6"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-101043"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/pnpm-11.0.0-before-11.11.0-environment-variable-exfiltration-via-proxy-settings"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/pnpm/pnpm","events":[{"introduced":"8aeeff4c46b939707fcb973c444c44809f691ef5"},{"fixed":"8e1e4c0aaece387dfda16377b2ba31f7a1a2602c"},{"introduced":"bd4caa505184c93a623595ecbb15edcf2ab24161"},{"fixed":"702ad5f860ffd50d64a3a711d9f8a3da16fc796e"}],"database_specific":{"extracted_events":[{"introduced":"11.0.0"},{"fixed":"11.11.0"},{"introduced":"10.7.0"},{"fixed":"10.34.5"}],"source":"AFFECTED_FIELD"}}],"versions":["v10.34.4","v11.10.0","v11.9.0","v11.8.0","v11.7.0","v11.6.0","v10.34.3","v10.34.2","v11.5.3","v10.34.1","v11.5.2","v11.5.1","v11.5.0","v11.4.0","v10.34.0","v11.3.0","v11.2.2","v11.2.1","v11.2.0","v11.1.3","v11.1.2-canora.8","v11.1.2-canora.7","v11.1.2-canora.10","v11.1.2","v11.1.1","v10.33.4","v11.1.0","v10.33.3","v10.33.2","v10.33.1","v11.0.0-rc.5","v11.0.0-rc.4","v11.0.0-rc.3","v11.0.0-rc.2","v11.0.0-rc.1","v10.33.0","v11.0.0-rc.0","v11.0.0-beta.8","v11.0.0-beta.7","v11.0.0-beta.6","v11.0.0-beta.5","v11.0.0-beta.4-1","v11.0.0-beta.4-0","v11.0.0-beta.4","v11.0.0-beta.3","v11.0.0-beta.2","v11.0.0-beta.1","v11.0.0-beta.0","v11.0.0-alpha.16","v11.0.0-alpha.15","v10.32.1","v10.32.0","v11.0.0-alpha.14","v10.31.0","v10.30.3","v11.0.0-alpha.13","v11.0.0-alpha.12","v10.30.2","v11.0.0-alpha.11","v11.0.0-alpha.10","v11.0.0-alpha.9","v11.0.0-alpha.8","v11.0.0-alpha.7","v11.0.0-alpha.6","v10.30.1","v10.30.0","v11.0.0-alpha.5","v11.0.0-alpha.4","v10.29.3","v10.29.2","v10.29.1","v10.29.0","v10.28.2","v10.28.1","v11.0.0-alpha.3","v10.28.0","v10.27.0","v10.26.2","v10.26.1","v11.0.0-alpha.2","v10.26.0","v10.25.0","v10.24.0","v10.23.0","v10.22.0","v11.0.0-alpha.1","v11.0.0-alpha.0","v10.21.0","v10.20.0","v10.19.1-oidc-test.3","v10.19.1-oidc-test.2","v10.19.1-oidc-test.1","v10.19.1-oidc-test.0","v10.19.0","v10.18.3","v10.18.2","v10.18.1","v10.18.0","v10.17.1","v10.17.0","v10.16.1","v10.16.0","v1","v10.15.1","v10.15.0","v10.14.0","v10.14.0-0","v10.13.1","v10.13.0","v10.12.4","v10.12.3","v10.12.2","v10.12.1","v10.11.0","v10.10.0","v10.9.0","v10.8.1","v10.8.0","v10.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-101043.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N"}]}