Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-10773

25
FAUCET Score

CVE-2019-10773 affects Yarn versions prior to 1.21.1, allowing attackers to create arbitrary symlinks on the host filesystem through specially crafted "bin" keys during package installation, potentially overwriting existing files. This vulnerability carries a high CVSS score of 7.8, indicating a local attack vector with low complexity, requiring user interaction, and leading to high impacts on confidentiality, integrity, and availability. While no public exploit intelligence (Metasploit, Nuclei, ExploitDB) or active exploitation (KEV) has been observed, and community discussion and media coverage are minimal, the potential for significant system compromise remains.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.21.1CPE matchmatch criteria
cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.50%
Probability of exploitation in next 30 days
EPSS Percentile
71.7%
Percentile rank of EPSS score among Peer Group
As of 2026-07-26
Model: v2026.06.15
This CVE's current EPSS score of 0.0150 is in the 70th percentile among its peer group of 11,616 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (3)

github_advisorypatch availablevia nvd_reference
View patch
npmpatch availablevia ghsa
Product: yarnFixed in: 1.22.0
redhatpatch availablevia redhat_api
Product: Red Hat Quay 3Fixed in: quay3/clair-jwt:v3.2.1-1
View patch

Vendor Advisories (2)

npmGHSA-5xf4-f2fq-f69jhigh

Yarn Improper link resolution before file access (Link Following)

Feb 14, 2020
redhatCVE-2019-10773Important

nodejs-yarn: Install functionality can be abused to generate arbitrary symlinks

Dec 16, 2019

References

access.redhat.com / errata/RHSA-2020:0475
blog.daniel-ruf.de / critical-design-flaw-npm-pnpm-yarn
ExploitThird Party Advisory
github.com / yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7
PatchThird Party Advisory
github.com / yarnpkg/yarn/issues/7761
ExploitThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/3HIZW4NZVV5QY5WWGW2JRP3FHYKZ6ZJ5
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ITY5BC63CCC647DFNUQRQ5AJDKUKUNBI
snyk.io / vuln/SNYK-JS-YARN-537806%2C