CVE-2025-69262 | pnpm up to 10.0.0 Environment Variable command injection
A vulnerability identified as critical has been detected in pnpm up to 10.0.0. Impacted is an unknown function of the component Environment Variable Handler. The manipulation leads to command injection.
This vulnerability is documented as CVE-2025-69262. The attack needs to be performed locally. There is not any exploit available.
You should upgrade the affected component.