Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Yarnpkg

First CVE: May 16, 2019Active for: 7 yearsTotal CVEs: 8

Yarn is a package manager for JavaScript that sits prominently in the software supply chain, embedded across development environments and CI/CD pipelines despite a narrow product scope. Its vulnerabilities recur through weakness classes including regular-expression denial of service, uncontrolled resource consumption, cleartext transmission of credentials, path traversal, and symlink-following, reflecting the dual challenges of parsing untrusted manifests and handling file operations in a package-installation context. Current severity, exploitation, and coverage counts are shown alongside this summary.

FAUCET AI Generated
8
Total CVEs
More Total CVEs than 90% of tracked vendors
1.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 12% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 50% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Yarnpkg over time

Volume of CVEsAvg CVSS Base Score
First CVE
May 16, 2019
7 years ago
Most Recent CVE
Aug 21, 2025
337 days ago

Products(2 total)

Top CVEs

Signals from CVEs in this vendor scope (8 CVEs).

8 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-8262HIGH
A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/
Jul 28, 20257.525NONO
CVE-2019-10773HIGH
In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files c
Dec 16, 20197.825NONO
CVE-2019-5448HIGH
Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network.
Jul 30, 20198.124NONO
CVE-2021-4435HIGH
An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be exec
Feb 4, 20247.823NONO
CVE-2020-8131HIGH
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing t
Feb 24, 20207.522NONO
CVE-2019-15608MEDIUM
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading
Mar 15, 20205.921NONO
CVE-2018-12556MEDIUM
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of
May 16, 20195.921NONO
CVE-2025-9308MEDIUM
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient r
Aug 21, 20255.520NONO
View all 8 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products8 CVEs
38%
63%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local3 (37.5%)
Network5 (62.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low4 (50.0%)
High4 (50.0%)
Unknown0 (0.0%)
User Interaction
None5 (62.5%)
Unknown0 (0.0%)
Required3 (37.5%)
Privileges Required
Low1 (12.5%)
High0 (0.0%)
None7 (87.5%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (8 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Yarnpkg.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Yarnpkg — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Yarnpkg's Products

View all 5 CNAs →

Top CWEs