Vulnerability index

Browse CVEs

8 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Yarn MEDIUM 5.5
CVE-2025-9308

A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such mani…

Fix: after 1.22.22
Fix from $1,600 2025-08-21
Yarn HIGH 7.5
CVE-2025-8262

A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of …

Fix: after 1.22.22
Fix from $1,950 2025-07-28
Yarn HIGH 7.8
CVE-2021-4435

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, m…

Fix: 1.22.13+
Fix from $1,950 2024-02-04
Yarn MEDIUM 5.9
CVE-2019-15608

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's …

Fix: 1.19.0+
Fix from $1,600 2020-03-15
Yarn HIGH 7.5
CVE-2020-8131EPSS 5%

Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitr…

Fix: after 1.21.1
Fix from $1,950 2020-02-24
Yarn HIGH 7.8
CVE-2019-10773

In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially craft…

Fix: 1.21.1+
Fix from $1,950 2019-12-16
Yarn HIGH 8.1
CVE-2019-5448

Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be s…

Fix: 1.17.3+
Fix from $1,950 2019-07-30
Website MEDIUM 5.9
CVE-2018-12556

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrar…

Fix: after 2018-06-05
Fix from $1,600 2019-05-16