OsVault/npm/yarn
npm

yarn

15 known vulnerabilities · 0 critical · 4 high

CVE-2019-5448HIGH

Missing Encryption of Sensitive Data in yarn

Published Jul 31, 2019
CVE-2020-8131HIGH

Path Traversal in Yarn

Published Feb 9, 2022
CVE-2019-10773HIGH

Yarn Improper link resolution before file access (Link Following)

Published Feb 14, 2020
CVE-2021-4435HIGH

Yarn untrusted search path vulnerability

Published Feb 4, 2024
CVE-2019-15608MEDIUM

TOCTOU Race Condition in Yarn

Published Feb 9, 2022
CVE-2025-59828

Claude Code Vulnerable to Arbitrary Code Execution via Plugin Autoloading with Specific Yarn Versions

Published Sep 24, 2025
MAL-2022-7330

Malicious code in yarn-design-system-rc-tooltip (npm)

Published Jun 20, 2022
MAL-2022-7325

Malicious code in yarn-design-system-choicesjs-stencil (npm)

Published Jun 20, 2022
MAL-2022-7327

Malicious code in yarn-design-system-fonts (npm)

Published Jun 20, 2022
MAL-2022-7326

Malicious code in yarn-design-system-flatpickr (npm)

Published Jun 20, 2022
MAL-2022-7328

Malicious code in yarn-design-system-logos (npm)

Published Jun 8, 2022
MAL-2022-7329

Malicious code in yarn-design-system-rc-input-number (npm)

Published Jun 20, 2022
MAL-2022-2914

Malicious code in example-yarn-package (npm)

Published Sep 12, 2022
MAL-2025-6137

Malicious code in yarn-test-git-repo (npm)

Published Jul 19, 2025
MAL-2022-7331

Malicious code in yarn-design-system-react-select (npm)

Published Jun 20, 2022
Check your entire dependency tree at onceRun dependency scan →