Yarn
This hub aggregates every CVE we track for Yarn, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
10
CVEs tracked
0
Critical
7
High
0
In CISA KEV
Severity distribution
HIGH7MEDIUM2LOW1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
1
1
0
0
0
0
0
0
0
0
0
0
2024-072026-06
Latest CVEs
The 10 most recently published vulnerabilities affecting Yarn.
- CVE-2025-9308yarnpkg Yarn request-manager.js setOptions redos3.3
- CVE-2025-8262yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos4.3
- CVE-2021-4435Yarn: untrusted search path7.7
- CVE-2019-15608The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. ...5.9
- CVE-2020-8131Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to instal...7.5
- CVE-2019-10773In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritt...7.8
- CVE-2019-16777Arbitrary File Overwrite in npm CLI7.7
- CVE-2019-16776Unauthorized File Access in npm CLI before before version 6.13.37.7
- CVE-2019-16775Unauthorized File Access in npm CLI before before version 6.13.37.7
- CVE-2019-5448Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.8.1
Product normalization is registry-driven with AI assist and human review. How it works