CVE-2025-9308
Published
CVSS v3
3.3
LOW
CVSS v2
1.7
LOW
Affected
1
PROJECT
Description
A vulnerability has been found in yarnpkg Yarn up to 1.22.22. This impacts the function setOptions of the file src/util/request-manager.js. Such manipulation leads to inefficient regular expression complexity. Local access is required to approach this attack. This vulnerability only affects products that are no longer supported by the maintainer.
The 1.x line is frozen - features and bugfixes now happen on https://github.com/yarnpkg/berry