An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
{
"severity": "HIGH",
"nvd_published_at": "2024-02-04T20:15:45Z",
"github_reviewed_at": "2024-02-05T20:20:29Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-426"
]
}