pnpm versions 11.0.0 before 11.11.0 and 10.7.0 before 10.34.5 expand ${VAR} environment-variable placeholders in the httpProxy, httpsProxy, and noProxy settings read from a project's pnpm-workspace.yaml. Because the manifest is repository-controlled and the proxy keys were omitted from the request-destination key set that otherwise suppresses placeholder expansion for untrusted manifests (as already done for registry, pnprServer, registries and namedRegistries), an attacker who controls a repository's pnpm-workspace.yaml can cause a victim who clones the repository and runs a pnpm command (e.g. pnpm install) to expand environment secrets such as NPM_TOKEN or GITHUB_TOKEN into a proxy hostname or userinfo and route install traffic — and the corresponding DNS lookups — through an attacker-controlled host. The exfiltration occurs during configuration loading, before any lifecycle script executes. Fixed in pnpm 11.11.0 and 10.34.5.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-101043 is a variable expansion vulnerability in pnpm package manager affecting versions 11.0.0 through 11.10.x and 10.7.0 through 10.34.4. The vulnerability allows environment variable placeholders (${VAR}) in proxy settings within pnpm-workspace.yaml files to be expanded when they should be treated as literal values. This matters because workspace configuration files are typically repository-controlled and may be committed to version control systems where attackers with repository access can inject malicious environment variable references. An attacker could craft a pnpm-workspace.yaml containing ${SENSITIVE_VAR} placeholders in httpProxy, httpsProxy, or noProxy settings to leak sensitive environment variables during package installation, potentially exposing credentials, API keys, or other secrets to remote proxy servers or logging systems. Development teams, CI/CD pipelines, and organizations using pnpm as their package manager are directly affected.
While MITRE ATT&CK techniques are not yet mapped to this vulnerability, Casky's skill library would detect attack patterns consistent with Credential Access (T1528 - Steal Application Access Token) and Collection (T1115 - Gather Victim Identity Information). Practitioners using Casky would observe findings related to: (1) Unsanitized variable references in configuration manifests that bypass security controls, (2) Environment variable leakage through proxy configurations, and (3) Configuration injection patterns where untrusted manifest data reaches security-sensitive settings. The extended reasoning capability would help practitioners understand the attack chain—how a compromised or malicious repository commit containing crafted ${VAR} references in pnpm-workspace.yaml can silently exfiltrate secrets during normal dependency resolution. Casky would flag the absence of input validation on proxy configuration fields and the inconsistent security handling compared to other sensitive registry settings.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-101043. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation