OsVault/npm/yaml
npm

yaml

18 known vulnerabilities · 0 critical · 1 high

CVE-2026-33532

yaml is vulnerable to Stack Overflow via deeply nested YAML collections

Published Mar 25, 2026
CVE-2023-2251HIGH

Uncaught Exception in yaml

Published Apr 24, 2023
CVE-2013-4660MEDIUM

Deserialization Code Execution in js-yaml

Published Oct 24, 2017
MAL-2022-1501

Malicious code in bender-lyaml-loader (npm)

Published Jun 20, 2022
CVE-2013-6393MEDIUM

Heap Based Buffer Overflow in libyaml

Published Aug 31, 2020
MAL-2023-981

Malicious code in yaml2binary (npm)

Published May 15, 2023
CVE-2025-64718

js-yaml has prototype pollution in merge (<<)

Published Nov 14, 2025
MAL-2024-11805

Malicious code in fake-yaml (npm)

Published Dec 12, 2024
MAL-2026-5193

Malicious code in javascript-yaml (npm)

Published Jun 4, 2026
MAL-2026-5194

Malicious code in yaml-javascript (npm)

Published Jun 4, 2026
MAL-2023-982

Malicious code in yaml2stream (npm)

Published Jun 22, 2023
GHSA-h67p-54hq-rp68

JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases

Published Jun 15, 2026
MAL-2023-975

Malicious code in xml2yaml (npm)

Published May 12, 2023
MAL-2025-4635

Malicious code in yaml-mcp-wrapper (npm)

Published Jun 2, 2025
MAL-2026-1242

Malicious code in yaml-manifest-utils-mynarratorai (npm)

Published Mar 4, 2026
GHSA-3f44-xw83-3pmg

Renovate vulnerable to arbitrary command injection via helmv3 manager and malicious Chart.yaml file

Published Jan 13, 2026
GHSA-x6p3-76f2-xxvh

Shamefile has an arbitrary file read via shamefile.yaml in shame next

Published May 28, 2026
GHSA-4936-9hrh-qqpw

@tinacms/cli: Remote Code Execution in @tinacms/cli via Forestry migration — unsanitised __TINA_INTERNAL__ marker in user-controlled YAML labels

Published Jun 19, 2026
Check your entire dependency tree at onceRun dependency scan →