An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
{
"cwe_ids": [
"CWE-426"
],
"github_reviewed": true,
"github_reviewed_at": "2024-02-05T20:20:29Z",
"nvd_published_at": "2024-02-04T20:15:45Z",
"severity": "HIGH"
}