Insertion of Sensitive Information Into Sent Data in pnpm - #VU134550
Published: June 15, 2026
pnpm
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to insertion of sensitive information into sent data in repository-controlled .npmrc and pnpm-workspace.yaml registry and auth configuration handling when processing environment variable placeholders in registry request destinations and credential values. A remote attacker can trick the victim into running a dependency-management command in a malicious repository to disclose sensitive information.
User interaction is required, and the disclosure can occur before lifecycle scripts run.