An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.
{ "nvd_published_at": "2024-02-04T20:15:45Z", "github_reviewed_at": "2024-02-05T20:20:29Z", "github_reviewed": true, "severity": "HIGH", "cwe_ids": [ "CWE-426" ] }