VDB
KO
HIGH 7.7

GHSA-mpwj-fcr6-x34c

Yarn untrusted search path vulnerability

Details

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / yarn
Introduced in: 0 Fixed in: 1.22.13
Fix npm install yarn@1.22.13

References