CVE-2025-69262 HIGH

CVE-2025-69262: pnpm vulnerable to Command Injection via environment variable substitution

Vendor Pnpm
Product pnpm
Weakness CWE-78
Published January 7, 2026
Last update February 26, 2026

CVSS base score

7.6/10
Attack vector Local
Attack complexity High
Privileges required High
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

Key dates

02Disclosure timeline

January 7, 2026 CVE published
February 26, 2026 Record updated