CVE-2026-55180Disclosure(pnpm / pnpm)

LOWCVSS 6.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch pnpm pnpm systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml into registry request destinations and registry credentials. A malicious repository could cause dependency resolution to send victim environment secrets to an attacker-selected registry before lifecycle scripts run. This vulnerability is fixed in 10.34.2 and 11.5.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-200CWE-201CWE-522

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pnpm

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 2 mentions (2026-06-25); latest day: 1
  • 4 total mentions across 3 days

Affected systems

Vendors
Products
pnpm

Deep dive

Activity timeline4 mentions / 3d
01122Mentions · 2026-06-25: 2Mentions · 2026-06-27: 1Mentions · 2026-09-01: 1Patch / Workaround · 2026-06-25: 1Technical Details · 2026-06-25: 1Technical Details · 2026-06-27: 1Technical Details · 2026-09-01: 106-2506-2709-01
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-06-252
General1Patch1
2026-06-271
Disclosure1
2026-09-011
Disclosure1
Full discourse4 posts
  • DailyCVE@dailycve
    Disclosure

    🟠 pnpm, Environment Variable Expansion via Proxy Settings, #CVE-2026-55180 (Medium) -DC-Sep2026-2063 https://dailycve.com/pnpm-environment-variable-expansion-via-proxy-settings-cve-2026-55180-medium-dc-sep2026-2063/

    Post summary

    A medium‑severity vulnerability (CVE‑2026‑55180) involving environment variable expansion via proxy settings in pnpm has been disclosed, with further details available on the linked DailyCVE page.

    0000038
    232 followersView on X
  • DailyCVE@dailycve
    Disclosure

    🔴 pnpm, Information Disclosure, #CVE-2026-55180 (High) -DC-Jun2026-712 https://dailycve.com/pnpm-information-disclosure-cve-2026-55180-high-dc-jun2026-712/

    Post summary

    The post announces a newly identified information disclosure vulnerability in pnpm (CVE‑2026‑55180) with high severity, providing a link for further details.

    0000058
    216 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-55180 Environment Variable Injection in pnpm Package Manager Versions B... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-55180 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The post merely announces the existence of CVE-2026-55180 with a link to a vulnerability database, providing no further detail on exploitation, patches, or technical specifics.

    0000094
    4.1K followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-55180 pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm and pacquet expanded ${ENV_VAR} placeholders from repository-controlled .npmrc and pnpm-workspace.yaml in… https://www.cve.org/CVERecord?id=CVE-2026-55180

    Post summary

    The snippet reports a CVE involving environment variable expansion in pnpm, noting that versions 10.34.2 and 11.5.3 contain a fix; no exploit, PoC, or active use details are present.

    00000934
    57.7K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Apppnpmpnpm-node.js-

Explore more