Yarn is a package manager for JavaScript that sits prominently in the software supply chain, embedded across development environments and CI/CD pipelines despite a narrow product scope. Its vulnerabilities recur through weakness classes including regular-expression denial of service, uncontrolled resource consumption, cleartext transmission of credentials, path traversal, and symlink-following, reflecting the dual challenges of parsing untrusted manifests and handling file operations in a package-installation context. Current severity, exploitation, and coverage counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Yarnpkg over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-8262HIGH A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/ | Jul 28, 2025 | 7.5 | 25 | NO | NO |
CVE-2019-10773HIGH In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files c | Dec 16, 2019 | 7.8 | 25 | NO | NO |
CVE-2019-5448HIGH Yarn before 1.17.3 is vulnerable to Missing Encryption of Sensitive Data due to HTTP URLs in lockfile causing unencrypted authentication data to be sent over the network. | Jul 30, 2019 | 8.1 | 24 | NO | NO |
CVE-2021-4435HIGH An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be exec | Feb 4, 2024 | 7.8 | 23 | NO | NO |
CVE-2020-8131HIGH Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing t | Feb 24, 2020 | 7.5 | 22 | NO | NO |
CVE-2019-15608MEDIUM The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading | Mar 15, 2020 | 5.9 | 21 | NO | NO |
CVE-2018-12556MEDIUM The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of | May 16, 2019 | 5.9 | 21 | NO | NO |
CVE-2025-9308MEDIUM A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient r | Aug 21, 2025 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Yarnpkg.
Media articles that mention a CVE ID that affects a product developed by Yarnpkg — matched by CVE ID, not by vendor name.