yarnpkg Vulnerabilities
CVE security advisories and vulnerability history for yarnpkg.
Overview
yarnpkg has 8 published CVE records since 2019, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 3 have a known public exploit. The average CVSS base score across scored CVEs is 6.6.
This page aggregates every publicly disclosed vulnerability (CVE) affecting yarnpkg products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
Security scorecard
A quick read on yarnpkg's vulnerability posture, as a share of its 8 published CVEs.
- Average CVSS
- 6.6
- Critical / high
- 50%
- Actively exploited (KEV)
- 0%
- Public exploit available
- 38%
- Patch available
- 88%
across 8 scored CVEs
4 of 8 scored
0 of 8 CVEs
3 of 8 CVEs
7 of 8 CVEs
Severity and exploitation
How the CVSS severity of yarnpkg's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.
In CISA’s Known Exploited Vulnerabilities catalog
0
None of yarnpkg's CVEs are currently listed in CISA's KEV catalog.
Public exploits
3
3 of yarnpkg's CVEs have a known public exploit available.
Most affected products
The yarnpkg products with the most published CVEs. Follow any product to browse its versions and vulnerabilities.
Common weakness types
The CWE weakness categories most often found in yarnpkg CVEs. Follow any weakness for its full explanation.
CNAs that assign these CVEs
The CVE Numbering Authorities that publish yarnpkg CVE records.
Disclosure activity by year
How many yarnpkg CVEs were published each year.
Latest yarnpkg CVEs
The most recently disclosed vulnerabilities affecting yarnpkg.
- Medium · CVSS 4.8EPSS 0.2%2025-08-21
- Medium · CVSS 5.3EPSS 0.7%2025-07-28
- High · CVSS 7.8EPSS 0.3%2024-02-04
- Medium · CVSS 5.9EPSS 1.8%2020-03-15
- High · CVSS 7.5EPSS 5.2%2020-02-24
- High · CVSS 7.8EPSS 1.5%2019-12-16
- High · CVSS 8.1EPSS 0.7%2019-07-30
- Medium · CVSS 5.9EPSS 1.8%2019-05-16
Track new yarnpkg CVEs as they are disclosed and get AI-written analysis and remediation guidance.
Monitor yarnpkg CVEsOther vendors
Browse vulnerabilities for other tracked vendors.
Frequently asked questions
Common questions about yarnpkg vulnerabilities.
- How many CVEs does yarnpkg have?
- yarnpkg has 8 published CVE records since 2019, including 2 in the last two years.
- How many yarnpkg CVEs are in CISA KEV?
- None of yarnpkg's CVEs are currently listed in CISA's Known Exploited Vulnerabilities catalog.
- Which yarnpkg products have the most CVEs?
- The yarnpkg products with the most published CVEs are Yarn, website.
- What are the most common weakness types in yarnpkg CVEs?
- yarnpkg's CVEs most often map to these CWE weakness types: CWE-1333 (Inefficient Regular Expression Complexity), CWE-22 (Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')), CWE-311 (Missing Encryption of Sensitive Data), CWE-426 (Untrusted Search Path).
- Are there public exploits for yarnpkg vulnerabilities?
- Yes — 3 of yarnpkg's CVEs have a known public exploit.
- What is the average severity of yarnpkg CVEs?
- The average CVSS base score across yarnpkg's scored CVEs is 6.6.
References
- The MITRE CVE Program (opens in a new tab)
- Learn: What is a CVE?
- CWE directory: the weakness types these CVEs map to
- CNA directory: the CNAs that assign these CVEs
Vulnerability data is sourced from the CVE Program; severity, KEV, and exploit signals are aggregated by RadicalNotion.AI.
Track yarnpkg vulnerabilities
Monitor new yarnpkg vulnerabilities as they are disclosed, with AI-written analysis and remediation guidance.