yarnpkg Vulnerabilities
CVE security advisories and vulnerability history for yarnpkg.
Overview
yarnpkg has 8 published CVE records since 2019, of which 0 are in CISA's Known Exploited Vulnerabilities catalog and 3 have a known public exploit. The average CVSS base score across scored CVEs is 5.9.
This page aggregates every publicly disclosed vulnerability (CVE) affecting yarnpkg products, with severity breakdowns, the most-affected products, the most common weakness types, and the latest disclosures.
Severity and exploitation
How the CVSS severity of yarnpkg's CVEs breaks down, plus how many are exploited in the wild or have public exploit code.