yarnpkg records
8 published records for vendor yarnpkg.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 1
- With a fix record
- 75%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-400 Uncontrolled Resource Consumption2
- CWE-311 Missing Encryption of Sensitive Data1
- CWE-347 Improper Verification of Cryptographic Signature1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-426 Untrusted Search Path1
- CWE-59 Improper Link Resolution Before File Access ('Link Following')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
8 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
32Monitor | CVE-2020-8131No exploit | Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead yarnpkg · yarn · CWE-22 | High7.5 | — | 5.2% | Feb 24, 2020 |
32Monitor | CVE-2019-5448No exploit | Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication datyarnpkg · yarn · CWE-311 | High8.1 | — | 0.7% | Jul 30, 2019 |
31Monitor | CVE-2019-10773No exploit | In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using speciayarnpkg · yarn · CWE-59 | High7.8 | — | 1.5% | Dec 16, 2019 |
31Monitor | CVE-2021-4435No exploit | Yarn: untrusted search pathyarnpkg · yarn · CWE-426 | High7.8 | — | 0.3% | Feb 4, 2024 |
24Monitor | CVE-2019-15608No exploit | The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cacyarnpkg · yarn · CWE-840 | Medium5.9 | — | 1.8% | Mar 15, 2020 |
24Monitor | CVE-2018-12556No exploit | The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any yarnpkg · website · CWE-347 | Medium5.9 | — | 1.8% | May 16, 2019 |
21Monitor | CVE-2025-8262No exploit | yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redosyarnpkg · yarn · CWE-400 | Medium5.3 | — | 0.7% | Jul 28, 2025 |
19Monitor | CVE-2025-9308No exploit | yarnpkg Yarn request-manager.js setOptions redosyarnpkg · yarn · CWE-400 | Medium4.8 | — | 0.2% | Aug 21, 2025 |
- CVE-2020-813132Monitor
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead
HighCVSS 7.5No exploitEPSS 5%yarnpkg · yarnFeb 24, 2020
- CVE-2019-544832Monitor
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication dat
HighCVSS 8.1No exploitEPSS 1%yarnpkg · yarnJul 30, 2019
- CVE-2019-1077331Monitor
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specia
HighCVSS 7.8No exploitEPSS 2%yarnpkg · yarnDec 16, 2019
- CVE-2021-443531Monitor
Yarn: untrusted search path
HighCVSS 7.8No exploitEPSS 0%yarnpkg · yarnFeb 4, 2024
- CVE-2019-1560824Monitor
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cac
MediumCVSS 5.9No exploitEPSS 2%yarnpkg · yarnMar 15, 2020
- CVE-2018-1255624Monitor
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any
MediumCVSS 5.9No exploitEPSS 2%yarnpkg · websiteMay 16, 2019
- CVE-2025-826221Monitor
yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos
MediumCVSS 5.3No exploitEPSS 1%yarnpkg · yarnJul 28, 2025
- CVE-2025-930819Monitor
yarnpkg Yarn request-manager.js setOptions redos
MediumCVSS 4.8No exploitEPSS 0%yarnpkg · yarnAug 21, 2025