OsVault/npm/yar
npm

yar

28 known vulnerabilities · 0 critical · 4 high

CVE-2014-4179

Denial of Service in yar

Published Sep 1, 2020
CVE-2026-25641

@nyariv/sandboxjs vulnerable to sandbox escape via TOCTOU bug on keys in property accesses

Published Feb 5, 2026
CVE-2019-5448HIGH

Missing Encryption of Sensitive Data in yarn

Published Jul 31, 2019
CVE-2025-59828

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

Published Sep 24, 2025
CVE-2026-25587

@nyariv/sandboxjs has a Sandbox Escape vulnerability

Published Feb 5, 2026
CVE-2020-8131HIGH

Path Traversal in Yarn

Published Feb 9, 2022
MAL-2022-7324

Malicious code in yargs-parxe (npm)

Published Aug 19, 2022
MAL-2022-7330

Malicious code in yarn-design-system-rc-tooltip (npm)

Published Jun 20, 2022
CVE-2019-10773HIGH

Yarn Improper link resolution before file access (Link Following)

Published Feb 14, 2020
CVE-2025-34146

@nyariv/sandboxjs has Prototype Pollution vulnerability that may lead to RCE

Published Jul 31, 2025
CVE-2021-4435HIGH

Yarn untrusted search path vulnerability

Published Feb 4, 2024
MAL-2022-7325

Malicious code in yarn-design-system-choicesjs-stencil (npm)

Published Jun 20, 2022
MAL-2022-7327

Malicious code in yarn-design-system-fonts (npm)

Published Jun 20, 2022
CVE-2026-25881

@nyariv/sandboxjs has host prototype pollution from sandbox via array intermediary (sandbox escape)

Published Feb 10, 2026
CVE-2026-25586

@nyariv/sandboxjs has Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution

Published Feb 5, 2026
CVE-2020-7608MEDIUM

yargs-parser Vulnerable to Prototype Pollution

Published Sep 4, 2020
MAL-2026-974

Malicious code in yarsg (npm)

Published Feb 20, 2026
CVE-2026-25520

@nyariv/sandboxjs has a Sandbox Escape issue

Published Feb 5, 2026
MAL-2022-7326

Malicious code in yarn-design-system-flatpickr (npm)

Published Jun 20, 2022
MAL-2022-7328

Malicious code in yarn-design-system-logos (npm)

Published Jun 8, 2022
MAL-2022-7329

Malicious code in yarn-design-system-rc-input-number (npm)

Published Jun 20, 2022
MAL-2022-6927

Malicious code in vidyard-player-sdk (npm)

Published Jun 20, 2022
MAL-2022-2914

Malicious code in example-yarn-package (npm)

Published Sep 12, 2022
MAL-2025-6137

Malicious code in yarn-test-git-repo (npm)

Published Jul 19, 2025
MAL-2022-7331

Malicious code in yarn-design-system-react-select (npm)

Published Jun 20, 2022
CVE-2019-15608MEDIUM

TOCTOU Race Condition in Yarn

Published Feb 9, 2022
MAL-2022-7280

Malicious code in xlhepkvdnjmyaruo (npm)

Published Jul 12, 2022
MAL-2026-207

Malicious code in yargs-js (npm)

Published Jan 12, 2026
Check your entire dependency tree at onceRun dependency scan →