{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-10-02T04:00:55.047","vulnerabilities":[{"cve":{"id":"CVE-2026-24910","sourceIdentifier":"cve@mitre.org","published":"2026-01-27T23:15:50.860","lastModified":"2026-06-17T10:23:47.740","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github)."},{"lang":"es","value":"En Bun antes de 1.3.5, la lista predeterminada de dependencias de confianza (también conocida como lista de permisos de confianza) puede ser suplantada por un paquete que no es de npm en caso de coincidencia de nombre (para archivo, enlace, git o github)."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"Bun","product":"Bun","defaultStatus":"unaffected","versions":[{"version":"0","lessThan":"1.3.5","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N","baseScore":5.9,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":1.4,"impactScore":4.0}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-28T21:19:41.436423Z","id":"CVE-2026-24910","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-348"}]}],"references":[{"url":"https://bun.com/blog/bun-v1.3.5","source":"cve@mitre.org"},{"url":"https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act","source":"cve@mitre.org"},{"url":"https://www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attack","source":"cve@mitre.org"}]}}]}