CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101043

HIGHCVSS 7.4NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-d

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-101043 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-101043

HIGHCVSS 7.4NVD feed

Published 27 September 2026 · tracked since 27 September 2026

Description

pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-d

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]