CVE-2025-9308

Published
View on NVD ↗
CVSS v3
3.3
LOW
CVSS v2
1.7
LOW
Affected
1
PROJECT

Description

A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.

The 1.x line is frozen - features and bugfixes now happen on https://github.com/yarnpkg/berry
GitHubGitHub
41.5K