P.01CVE-2026-50017: pnpm Leaked npm Auth Tokens to Untrusted Registries. Are You Patched?
pnpm versions before 10.34.0 and 11.4.0 could send your unscoped npm auth token to whatever registry a repository's .npmrc pointed at. Here's how the leak works, who's exposed, and how to check and fix it.





