yarnpkg
Security Risk Profile
27
/100
lowSecurity Risk Score
Comprehensive risk assessment based on 8 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from May 16, 2019 to present
8
Total CVEs
4
Critical+High
0
Exploited
1
Unpatched
Threat Assessment
Avg CVSS
6.7
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
1
Critical/High
Risk Level
27/100
low
Severity Distribution
Critical
0High
4Medium
4Low
0Exploit Likelihood
>50% chance
020-50%
05-20%
0<5%
2Age Distribution
Common Weaknesses (CWE)
1
Path Traversal
1
2
Command Injection
1
3
OS Command Injection
1
Most Affected Products
1. yarnpkg yarn9
2. redhat/yarn3
3. npm/yarn3
4. yarnpkg website1
Recent Vulnerabilities
See more →CVE-2025-9308
CVSS 5.5EPSS 0%medium
yarnpkg Yarn request-manager.js setOptions redos
8/21/2025🔧 No Patch
CVE-2025-8262
CVSS 5.3EPSS 0%medium
yarnpkg Yarn hosted-git-resolver.js explodeHostedGitFragment redos
7/28/2025🔧 No Patch
CVE-2021-4435
CVSS 7.8high
Yarn: untrusted search path
2/1/2024
CVE-2019-15608
CVSS 5.9medium
3/15/2020
CVE-2020-8131
CVSS 7.5high
2/14/2020
CVE-2019-10773
CVSS 7.8high
12/16/2019
CVE-2019-5448
CVSS 8.1high
7/30/2019🔧 No Patch
CVE-2018-12556
CVSS 5.9medium
5/16/2019🔧 No Patch
Monitor yarnpkg in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.