pnpm vulnerable to Command Injection via environment variable substitution
Published Jan 7, 2026
7.8
HIGHCVSS 3.1
EPSS 1.04%
Description
pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.
Affected products
-
- Version >=6.25.0, < 10.27.0StatusaffectedConstraints-
- Version
No data.
Red Hat JBoss Enterprise Application Platform 8
org.keycloak-keycloak-parent
Not affected
Red Hat JBoss Enterprise Application Platform Expansion Pack
org.keycloak-keycloak-parent
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat JBoss Enterprise Application Platform 8 | org.keycloak-keycloak-parent | Not affected | n/a |
| Red Hat JBoss Enterprise Application Platform Expansion Pack | org.keycloak-keycloak-parent | Not affected | n/a |
pnpm
npm
Introduced 6.25.0 Fixed 10.27.0
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| npm | pnpm | 6.25.0 | 10.27.0 |
Remediation
Red Hat statement
This vulnerability is rated Moderate for Red Hat. The flaw in pnpm allows for remote code execution via command injection when environment variable substitution is used in `.npmrc` files with `tokenHelper` settings. Exploitation requires an attacker to control environment variables and place malicious scripts, primarily impacting build environments such as CI/CD pipelines or Docker builds. Red Hat products like Enterprise Application Platform are not directly affected by this pnpm vulnerability.
Red Hat mitigation
To reduce exposure, avoid using the tokenHelper setting in .npmrc configuration files. Instead, configure authentication using direct tokens. It is also recommended to audit and restrict environment variables in build environments, including CI/CD pipelines and container build processes, to prevent unauthorized control.
References (9)
- https://access.redhat.com/security/cve/CVE-2025-69262 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2427662 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1159 Advisory
- https://github.com/advisories/GHSA-2phv-j68v-wwqx Advisory
- https://github.com/pnpm/pnpm
- https://github.com/pnpm/pnpm/releases/tag/v10.27.0 x_refsource_MISCProductRelease Notes
- https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx exploitx_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2025-69262
- https://www.cve.org/CVERecord?id=CVE-2025-69262
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2025-69262 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2427662 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-1159 | Advisory | |
| https://github.com/advisories/GHSA-2phv-j68v-wwqx | Advisory | |
| https://github.com/pnpm/pnpm | ||
| https://github.com/pnpm/pnpm/releases/tag/v10.27.0 | x_refsource_MISCProductRelease Notes | |
| https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx | exploitx_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2025-69262 | ||
| https://www.cve.org/CVERecord?id=CVE-2025-69262 |
Change history (0)
No recorded changes yet.