Inclusion of Sensitive Information in Log Files in pnpm - #VU153399
Published: October 6, 2026
Vulnerability details
The vulnerability allows a local user to disclose registry usernames and passwords.
The vulnerability exists due to inclusion of sensitive information in warning output when reporting ignored project .npmrc registry and authentication settings. A local user can read warnings containing credentials from URL-scoped configuration keys to disclose registry usernames and passwords.
The exposed credentials are embedded in the URL portion of a configuration key, such as //user:password@registry.example.com/:_authToken.