zc_plugin_dm
zc_plugin_dm copied to clipboard
CVE-2025-8262 (High) detected in yarn-1.22.11.tgz
CVE-2025-8262 - High Severity Vulnerability
Vulnerable Library - yarn-1.22.11.tgz
?? Fast, reliable, and secure dependency management.
Library home page: https://registry.npmjs.org/yarn/-/yarn-1.22.11.tgz
Path to dependency file: /dmreactplugin/package.json
Path to vulnerable library: /dmreactplugin/package.json
Dependency Hierarchy:
- :x: yarn-1.22.11.tgz (Vulnerable Library)
Found in HEAD commit: 41f949b863ead7c74b72a01845dbe0d88c24a364
Found in base branch: main
Vulnerability Details
A vulnerability was found in yarnpkg Yarn up to 1.22.22. It has been classified as problematic. Affected is the function explodeHostedGitFragment of the file src/resolvers/exotics/hosted-git-resolver.js. The manipulation leads to inefficient regular expression complexity. It is possible to launch the attack remotely. The patch is identified as 97731871e674bf93bcbf29e9d3258da8685f3076. It is recommended to apply a patch to fix this issue.
Publish Date: 2025-07-28
URL: CVE-2025-8262
CVSS 3 Score Details (7.5)
Base Score Metrics:
- Exploitability Metrics:
- Attack Vector: Network
- Attack Complexity: Low
- Privileges Required: None
- User Interaction: None
- Scope: Unchanged
- Impact Metrics:
- Confidentiality Impact: None
- Integrity Impact: None
- Availability Impact: High
Step up your Open Source Security Game with Mend here