Medium severity5.9NVD Advisory· Published Mar 15, 2020· Updated Jun 17, 2026
CVE-2019-15608
CVE-2019-15608
Description
The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
yarnnpm | < 1.19.0 | 1.19.0 |
Affected products
5- yarn/yarndescription
- osv-coords3 versions
< 1.19.0-r0+ 2 more
- (no CPE)range: < 1.19.0-r0
- (no CPE)range: < 1.19.0-r0
- (no CPE)range: < 1.19.0
Patches
Vulnerability mechanics
References
5- hackerone.com/reports/703138nvdExploitMitigationThird Party AdvisoryWEB
- github.com/advisories/GHSA-hjxc-462x-x77jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2019-15608ghsaADVISORY
- github.com/yarnpkg/yarn/blob/master/CHANGELOG.mdnvdWEB
- github.com/yarnpkg/yarn/commit/0474b8c66a8ea298f5e4dedc67b2de464297ad1cnvdWEB
News mentions
0No linked articles in our index yet.