{"id":"CVE-2025-69262","title":"pnpm is a package manager","summary":"pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environme…","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H","cwe":["CWE-78","CWE-94"],"published":"2026-01-07","updated":"2026-06-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-69262","references":[{"url":"https://github.com/pnpm/pnpm/releases/tag/v10.27.0","label":"security-advisories@github.com"},{"url":"https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx","label":"security-advisories@github.com"},{"url":"https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx","label":"134c704f-9b21-4f2e-91b3-4a467353bcc0"},{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69262.json"},{"url":"https://access.redhat.com/security/cve/CVE-2025-69262"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2427662"},{"url":"https://www.cve.org/CVERecord?id=CVE-2025-69262"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2025-69262"},{"url":"https://github.com/pnpm/pnpm"}],"tags":["nvd","csaf","vex","red-hat"],"epss":0.01057,"epssPercentile":0.625,"ingestedAt":"2026-06-29T13:24:34.626Z","vendor":"Red Hat","slug":"CVE-2025-69262","body":"## Overview\n\npnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Vendor advisories\n\n- **Red Hat VEX** · Moderate · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69262.json)","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}