Security
Headlines
HeadlinesLatestCVEs

Headline

GHSA-mpwj-fcr6-x34c: Yarn untrusted search path vulnerability

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

ghsa
#vulnerability#nodejs#git

Yarn untrusted search path vulnerability

High severity GitHub Reviewed Published Feb 4, 2024 to the GitHub Advisory Database • Updated Feb 5, 2024

ghsa: Latest News

GHSA-g85v-wf27-67xc: Harden-Runner has a command injection weaknesses in `setup.ts` and `arc-runner.ts`