VYPR

Bun

by Oven Sh

Source repositories

CVEs (2)

  • CVE-2024-21548HigDec 18, 2024
    risk 0.42cvss 7.5epss 0.01

    Versions of the package bun after 0.0.12 and before 1.1.30 are vulnerable to Prototype Pollution due to improper input sanitization. An attacker can exploit this vulnerability through Bun's APIs that accept objects. **Note:** This issue relates to the widely known and actively…

  • CVE-2026-24910MedJan 27, 2026
    risk 0.38cvss 5.9epss 0.00

    In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).