Skip to content
Noroxi

yarnpkg records

8 published records for vendor yarnpkg.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
75%
Median publish → KEV
No record has entered KEV

All records

8 records
  • CVE-2020-8131
    32Monitor

    Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead

    HighCVSS 7.5No exploitEPSS 5%

    yarnpkg · yarnFeb 24, 2020

  • CVE-2019-5448
    32Monitor

    Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication dat

    HighCVSS 8.1No exploitEPSS 1%

    yarnpkg · yarnJul 30, 2019

  • In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specia

    HighCVSS 7.8No exploitEPSS 2%

    yarnpkg · yarnDec 16, 2019

  • CVE-2021-4435
    31Monitor

    Yarn: untrusted search path

    HighCVSS 7.8No exploitEPSS 0%

    yarnpkg · yarnFeb 4, 2024

  • The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cac

    MediumCVSS 5.9No exploitEPSS 2%

    yarnpkg · yarnMar 15, 2020

  • The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any

    MediumCVSS 5.9No exploitEPSS 2%

    yarnpkg · websiteMay 16, 2019

  • CVE-2025-8262
    21Monitor

    yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos

    MediumCVSS 5.3No exploitEPSS 1%

    yarnpkg · yarnJul 28, 2025

  • CVE-2025-9308
    19Monitor

    yarnpkg Yarn request-manager.js setOptions redos

    MediumCVSS 4.8No exploitEPSS 0%

    yarnpkg · yarnAug 21, 2025