Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-0674 | An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways. |
Github GHSA |
GHSA-mpwj-fcr6-x34c | Yarn untrusted search path vulnerability |
Tue, 17 Jun 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 May 2025 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Thu, 22 May 2025 02:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
Status: PUBLISHED
Assigner: fedora
Published:
Updated: 2025-06-17T14:29:17.224Z
Reserved: 2024-02-01T14:23:02.896Z
Link: CVE-2021-4435
Updated: 2024-08-03T17:30:07.387Z
Status : Modified
Published: 2024-02-04T20:15:45.657
Modified: 2024-11-21T06:37:43.400
Link: CVE-2021-4435
OpenCVE Enrichment
No data.
EUVD
Github GHSA