---
id: CVE-2025-69262
title: pnpm is a package manager
summary: >-
  pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command
  Injection vulnerability when using environment variable substitution in .npmrc
  configuration files with tokenHelper settings. An attacker who can control
  environme…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H'
cwe:
  - CWE-78
  - CWE-94
published: '2026-01-07'
updated: '2026-06-22'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69262'
references:
  - url: 'https://github.com/pnpm/pnpm/releases/tag/v10.27.0'
    label: security-advisories@github.com
  - url: 'https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx'
    label: security-advisories@github.com
  - url: 'https://github.com/pnpm/pnpm/security/advisories/GHSA-2phv-j68v-wwqx'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69262.json
  - url: 'https://access.redhat.com/security/cve/CVE-2025-69262'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2427662'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2025-69262'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2025-69262'
  - url: 'https://github.com/pnpm/pnpm'
tags:
  - nvd
  - csaf
  - vex
  - red-hat
epss: 0.01057
epssPercentile: 0.62998
ingestedAt: '2026-06-29T13:24:34.626Z'
vendor: Red Hat
---

## Overview

pnpm is a package manager. Versions 6.25.0 through 10.26.2 have a Command Injection vulnerability when using environment variable substitution in .npmrc configuration files with tokenHelper settings. An attacker who can control environment variables during pnpm operations could achieve Remote Code Execution (RCE) in build environments. This issue is fixed in version 10.27.0.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Vendor advisories

- **Red Hat VEX** · Moderate · updated 2026-09-12 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2025/cve-2025-69262.json)
