Inclusion of Sensitive Information in Log Files in pnpm - #VU153380

 

Inclusion of Sensitive Information in Log Files in pnpm - #VU153380

Published: October 6, 2026


Vulnerability identifier: #VU153380
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-532
Exploitation vector: Local access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local user to obtain registry usernames and passwords from warning output.

The vulnerability exists due to inclusion of sensitive information in warning output in project .npmrc registry warnings when reporting an ignored registry setting containing a URL-scoped key with embedded credentials. A local user can read the emitted warning to obtain registry usernames and passwords from warning output.


Affected software

pnpm

Remediation

Install security update from vendor's website.

pnpm - update to 12.10.0

External References

Related Security Bulletins