Bug 2542146 (CVE-2026-101043)
| Summary: | CVE-2026-101043 pnpm: pnpm: Information disclosure via environment variable expansion in proxy settings | ||
|---|---|---|---|
| Product: | [Other] Security Response | Reporter: | OSIDB Bzimport <bzimport> |
| Component: | vulnerability | Assignee: | Product Security DevOps Team <prodsec-dev> |
| Status: | NEW --- | QA Contact: | |
| Severity: | high | Docs Contact: | |
| Priority: | high | ||
| Version: | unspecified | CC: | anjoseph, anujha, aschwart, asoldano, aszczucz, ataylor, bbaranow, bmaxwell, boliveir, bstansbe, csuconic, dbruscin, dlofthou, drichtar, ehugonne, gbenhaim, gtully, istudens, ivassile, iweiss, jprabhak, jsherman, kvanderr, mosmerov, mposolda, msvehla, niyer, nwallace, pberan, pesilva, pjindal, pmackay, rgemmell, rgodfrey, rmartinc, rstancel, ssilvert, sthorger, tbish, thjenkin, tlavocat, twaugh, vdosoudi, vmuzikar, wtam |
| Target Milestone: | --- | Keywords: | Security |
| Target Release: | --- | ||
| Hardware: | All | ||
| OS: | Linux | ||
| Whiteboard: | |||
| Fixed In Version: | Doc Type: | --- | |
| Doc Text: |
A flaw was found in pnpm. This vulnerability can lead to information disclosure because proxy settings defined in workspace configuration files expand environment variable placeholders without proper restrictions. An attacker who convinces a user or automated system to run a command within a malicious repository can capture sensitive environment variables, such as authentication tokens. During configuration loading, pnpm routes network and Domain Name System (DNS) requests containing these secret values to an attacker-controlled server.
|
Story Points: | --- |
| Clone Of: | Environment: | ||
| Last Closed: | Type: | --- | |
| Regression: | --- | Mount Type: | --- |
| Documentation: | --- | CRM: | |
| Verified Versions: | Category: | --- | |
| oVirt Team: | --- | RHEL 7.3 requirements from Atomic Host: | |
| Cloudforms Team: | --- | Target Upstream Version: | |
| Embargoed: | |||
pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-destination key set that otherwise suppresses placeholder expansion for untrusted manifests (as already done for registry, pnprServer, registries and namedRegistries), an attacker who controls a repository's pnpm-workspace.yaml can cause a victim who clones the repository and runs a pnpm command (e.g. pnpm install) to expand environment secrets such as NPM_TOKEN or GITHUB_TOKEN into a proxy hostname or userinfo and route install traffic — and the corresponding DNS lookups — through an attacker-controlled host. The exfiltration occurs during configuration loading, before any lifecycle script executes. Fixed in pnpm 11.11.0 and 10.34.5.