{"api_version":"1","generated_at":"2026-07-24T18:26:08+00:00","cve":"CVE-2019-10773","urls":{"html":"https://cve.report/CVE-2019-10773","api":"https://cve.report/api/cve/CVE-2019-10773.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-10773","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-10773"},"summary":{"title":"CVE-2019-10773","description":"In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted \"bin\" keys. Existing files could be overwritten depending on the current user permission set.","state":"PUBLIC","assigner":"report@snyk.io","published_at":"2019-12-16 20:15:00","updated_at":"2023-11-07 03:02:00"},"problem_types":["CWE-59"],"metrics":[],"references":[{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HIZW4NZVV5QY5WWGW2JRP3FHYKZ6ZJ5/","name":"FEDORA-2020-7525beefa1","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 30 Update: nodejs-yarn-1.21.1-1.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://access.redhat.com/errata/RHSA-2020:0475","name":"RHSA-2020:0475","refsource":"REDHAT","tags":[],"title":"Red Hat Customer Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7","name":"https://github.com/yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7","refsource":"MISC","tags":["Patch","Third Party Advisory"],"title":"Fixes bin overwrites (#7755) · yarnpkg/yarn@039bafd · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/SNYK-JS-YARN-537806%2C","name":"https://snyk.io/vuln/SNYK-JS-YARN-537806%2C","refsource":"","tags":[],"title":"Page not found | Snyk","mime":"text/html","httpstatus":"422","archivestatus":"404"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ITY5BC63CCC647DFNUQRQ5AJDKUKUNBI/","name":"FEDORA-2020-766ce5adae","refsource":"","tags":[],"title":"[SECURITY] Fedora 31 Update: nodejs-yarn-1.21.1-1.fc31 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3HIZW4NZVV5QY5WWGW2JRP3FHYKZ6ZJ5/","name":"FEDORA-2020-7525beefa1","refsource":"","tags":[],"title":"[SECURITY] Fedora 30 Update: nodejs-yarn-1.21.1-1.fc30 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITY5BC63CCC647DFNUQRQ5AJDKUKUNBI/","name":"FEDORA-2020-766ce5adae","refsource":"FEDORA","tags":[],"title":"[SECURITY] Fedora 31 Update: nodejs-yarn-1.21.1-1.fc31 - package-announce - Fedora Mailing-Lists","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://snyk.io/vuln/SNYK-JS-YARN-537806,","name":"https://snyk.io/vuln/SNYK-JS-YARN-537806,","refsource":"MISC","tags":["Broken Link"],"title":"Invalid vulnerability","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"https://github.com/yarnpkg/yarn/issues/7761#issuecomment-565493023","name":"https://github.com/yarnpkg/yarn/issues/7761#issuecomment-565493023","refsource":"CONFIRM","tags":["Exploit","Third Party Advisory"],"title":"globally-installed package overwrites an existing binary in the target install location · Issue #7761 · yarnpkg/yarn · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://blog.daniel-ruf.de/critical-design-flaw-npm-pnpm-yarn/","name":"https://blog.daniel-ruf.de/critical-design-flaw-npm-pnpm-yarn/","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"binary planting and arbitrary file (over)write vulnerabilities in npm, pnpm and yarn | Blog of Daniel Ruf","mime":"text/html","httpstatus":"200","archivestatus":"403"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-10773","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10773","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"10773","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yarnpkg","cpe5":"yarn","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"10773","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yarnpkg","cpe5":"yarn","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2019-10773","qid":"981590","title":"Nodejs (npm) Security Update for yarn (GHSA-5xf4-f2fq-f69j)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2019-10773","ASSIGNER":"report@snyk.io","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"Yarn","version":{"version_data":[{"version_value":"All versions prior to version 1.21.1"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Arbitrary File Write"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://snyk.io/vuln/SNYK-JS-YARN-537806,","url":"https://snyk.io/vuln/SNYK-JS-YARN-537806,"},{"refsource":"MISC","name":"https://github.com/yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7","url":"https://github.com/yarnpkg/yarn/commit/039bafd74b7b1a88a53a54f8fa6fa872615e90e7"},{"refsource":"CONFIRM","name":"https://github.com/yarnpkg/yarn/issues/7761#issuecomment-565493023","url":"https://github.com/yarnpkg/yarn/issues/7761#issuecomment-565493023"},{"refsource":"MISC","name":"https://blog.daniel-ruf.de/critical-design-flaw-npm-pnpm-yarn/","url":"https://blog.daniel-ruf.de/critical-design-flaw-npm-pnpm-yarn/"},{"refsource":"FEDORA","name":"FEDORA-2020-766ce5adae","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ITY5BC63CCC647DFNUQRQ5AJDKUKUNBI/"},{"refsource":"FEDORA","name":"FEDORA-2020-7525beefa1","url":"https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/3HIZW4NZVV5QY5WWGW2JRP3FHYKZ6ZJ5/"},{"refsource":"REDHAT","name":"RHSA-2020:0475","url":"https://access.redhat.com/errata/RHSA-2020:0475"}]},"description":{"description_data":[{"lang":"eng","value":"In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted \"bin\" keys. Existing files could be overwritten depending on the current user permission set."}]}},"nvd":{"publishedDate":"2019-12-16 20:15:00","lastModifiedDate":"2023-11-07 03:02:00","problem_types":["CWE-59"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":6.8},"severity":"MEDIUM","exploitabilityScore":8.6,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*","versionEndExcluding":"1.21.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"10773","Ordinal":"149052","Title":"CVE-2019-10773","CVE":"CVE-2019-10773","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"10773","Ordinal":"1","NoteData":"In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted \"bin\" keys. Existing files could be overwritten depending on the current user permission set.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"10773","Ordinal":"2","NoteData":"2019-12-16","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"10773","Ordinal":"3","NoteData":"2020-02-11","Type":"Other","Title":"Modified"}]}}}