VYPR
High severity7.7NVD Advisory· Published Feb 4, 2024· Updated Jun 17, 2026

CVE-2021-4435

CVE-2021-4435

Description

An untrusted search path vulnerability was found in Yarn. When a victim runs certain Yarn commands in a directory with attacker-controlled content, malicious commands could be executed in unexpected ways.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
yarnnpm
< 1.22.131.22.13

Affected products

6

Patches

Vulnerability mechanics

References

6

News mentions

0

No linked articles in our index yet.