Security Digest: January 7, 2026 - 3 Critical Vulnerabilities

Stay vigilant as three critical vulnerabilities have been identified in pnpm and related components, risking code execution and supply chain attacks.

· 3 min read

Today's Top Security Threats

Stay vigilant as three critical vulnerabilities have been identified in pnpm and related components, risking code execution and supply chain attacks. Immediate action is required to secure affected systems.

Critical Vulnerabilities

  • CVE-2025-69264: pnpm v10+ Git Dependency Script Execution Bypass
    • Impact: Allows remote code execution during package installation via git-hosted dependencies, bypassing default script execution blocks.
    • Affected Systems: pnpm v10.0.0 and later
    • Immediate Action: Disable script execution in your pnpm configuration and audit your git dependencies.
    • Mitigation: Implement strict allowlists and monitor dependency updates.
  • CVE-2025-69262: Environment Variable Injection in pnpm
    • Impact: Enables command injection through .npmrc configuration, leading to potential remote code execution.
    • Affected Systems: All pnpm versions using `@pnpm/config.env-replace`
    • Immediate Action: Review and sanitize environment variables; disable tokenHelper in .npmrc.
    • Mitigation: Use direct authentication tokens and audit all scripts and configurations.
  • CVE-2025-69263: Lack of Integrity Verification for HTTP Tarball Dependencies
    • Impact: Allows attackers to serve modified tarball content, bypassing lockfile security.
    • Affected Systems: pnpm installations using HTTP tarball URLs
    • Immediate Action: Avoid using HTTP tarball dependencies; switch to secure package registries.
    • Mitigation: Regularly audit dependency sources and enforce HTTPS with integrity checks.

Previously Alerted

What to Do Now

  1. Review all pnpm configurations and dependencies immediately.
  2. Disable unauthorized scripts and audit environment variables thoroughly.
  3. Switch to secure package sources and enforce integrity checks.
  4. Implement continuous monitoring for unusual network and file activity.

Related Resources

  • Official pnpm advisories on GitHub
  • Internal blog posts on supply chain security (available soon)

Keep reading