{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-06-15T03:00:24.883","vulnerabilities":[{"cve":{"id":"CVE-2019-10773","sourceIdentifier":"report@snyk.io","published":"2019-12-16T20:15:14.477","lastModified":"2024-11-21T04:19:53.623","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted \"bin\" keys. Existing files could be overwritten depending on the current user permission set."},{"lang":"es","value":"En Yarn versiones anteriores a 1.21.1, la funcionalidad package install puede ser abusada para generar enlaces simbólicos arbitrarios en el sistema de archivos host mediante el uso de teclas \"bin\" especialmente diseñadas. Los archivos existentes podrían ser sobrescritos dependiendo del conjunto de permisos del usuario actual."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","baseScore":6.8,"accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-59"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*","versionEndExcluding":"1.21.1","matchCriteriaId":"6AD33651-1103-4375-8BCF-983DBCDF6470"}]}]}],"references":[{"url":"https://access.redhat.com/errata/RHSA-2020:0475","source":"report@snyk.io"},{"url":"https://blog.daniel-ruf.de/critical-design-flaw-npm-pnpm-yarn/","source":"report@snyk.io","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7","source":"report@snyk.io","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/yarnpkg/yarn/issues/7761#issuecomment-565493023","source":"report@snyk.io","tags":["Exploit","Third Party Advisory"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HIZW4NZVV5QY5WWGW2JRP3FHYKZ6ZJ5/","source":"report@snyk.io"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITY5BC63CCC647DFNUQRQ5AJDKUKUNBI/","source":"report@snyk.io"},{"url":"https://snyk.io/vuln/SNYK-JS-YARN-537806%2C","source":"report@snyk.io"},{"url":"https://access.redhat.com/errata/RHSA-2020:0475","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://blog.daniel-ruf.de/critical-design-flaw-npm-pnpm-yarn/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Third Party Advisory"]},{"url":"https://github.com/yarnpkg/yarn/issues/7761#issuecomment-565493023","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Third Party Advisory"]},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HIZW4NZVV5QY5WWGW2JRP3FHYKZ6ZJ5/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITY5BC63CCC647DFNUQRQ5AJDKUKUNBI/","source":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://snyk.io/vuln/SNYK-JS-YARN-537806%2C","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}