Inclusion of Sensitive Information in Log Files in pnpm - #VU153380
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to obtain registry usernames and passwords from warning output.
The vulnerability exists due to inclusion of sensitive information in warning output in project .npmrc registry warnings when reporting an ignored registry setting containing a URL-scoped key with embedded credentials. A local user can read the emitted warning to obtain registry usernames and passwords from warning output.