{"api_version":"1","generated_at":"2026-07-23T09:19:17+00:00","cve":"CVE-2020-8131","urls":{"html":"https://cve.report/CVE-2020-8131","api":"https://cve.report/api/cve/CVE-2020-8131.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2020-8131","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2020-8131"},"summary":{"title":"CVE-2020-8131","description":"Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.","state":"PUBLIC","assigner":"support@hackerone.com","published_at":"2020-02-24 15:15:00","updated_at":"2020-03-24 14:47:00"},"problem_types":["CWE-22"],"metrics":[],"references":[{"url":"https://github.com/yarnpkg/yarn/pull/7831","name":"https://github.com/yarnpkg/yarn/pull/7831","refsource":"CONFIRM","tags":["Patch","Third Party Advisory"],"title":"Fixes arbitrary file write on fetch by arcanis · Pull Request #7831 · yarnpkg/yarn · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://hackerone.com/reports/730239","name":"https://hackerone.com/reports/730239","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"HackerOne","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2020-8131","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2020-8131","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2020","cve_id":"8131","vulnerable":"1","versionEndIncluding":"1.21.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"yarnpkg","cpe5":"yarn","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[{"cve":"CVE-2020-8131","qid":"180708","title":"Debian Security Update for node-yarnpkg (CVE-2020-8131)"}]},"source_records":{"cve_program":{"data_type":"CVE","data_format":"MITRE","data_version":"4.0","CVE_data_meta":{"ID":"CVE-2020-8131","ASSIGNER":"support@hackerone.com","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"vendor_name":"n/a","product":{"product_data":[{"product_name":"yarn","version":{"version_data":[{"version_value":"Fixed Version: 1.22.0"}]}}]}}]}},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Path Traversal (CWE-22)"}]}]},"references":{"reference_data":[{"refsource":"MISC","name":"https://hackerone.com/reports/730239","url":"https://hackerone.com/reports/730239"},{"refsource":"CONFIRM","name":"https://github.com/yarnpkg/yarn/pull/7831","url":"https://github.com/yarnpkg/yarn/pull/7831"}]},"description":{"description_data":[{"lang":"eng","value":"Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package."}]}},"nvd":{"publishedDate":"2020-02-24 15:15:00","lastModifiedDate":"2020-03-24 14:47:00","problem_types":["CWE-22"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.5,"baseSeverity":"HIGH"},"exploitabilityScore":1.6,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:H/Au:N/C:P/I:P/A:P","accessVector":"NETWORK","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL","baseScore":5.1},"severity":"MEDIUM","exploitabilityScore":4.9,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:yarnpkg:yarn:*:*:*:*:*:*:*:*","versionEndIncluding":"1.21.1","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2020","CveId":"8131","Ordinal":"168468","Title":"CVE-2020-8131","CVE":"CVE-2020-8131","Year":"2020"},"notes":[{"CveYear":"2020","CveId":"8131","Ordinal":"1","NoteData":"Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.","Type":"Description","Title":null},{"CveYear":"2020","CveId":"8131","Ordinal":"2","NoteData":"2020-02-24","Type":"Other","Title":"Published"},{"CveYear":"2020","CveId":"8131","Ordinal":"3","NoteData":"2020-02-28","Type":"Other","Title":"Modified"}]}}}