CVE-2020-8131
Path Traversal in Yarn
7.5
HIGH
CVSS 3.1
EPSS 5.0%
Description
Arbitrary filesystem write vulnerability in Yarn before 1.22.0 allows attackers to write to any path on the filesystem and potentially lead to arbitrary code execution by forcing the user to install a malicious package.
How to fix CVE-2020-8131
To remediate CVE-2020-8131, upgrade the affected package to a fixed version below.
- Debian/node-yarnpkg—upgrade to 1.22.4-2 or later
- —upgrade to 1.22.0 or later
Is CVE-2020-8131 being exploited?
Moderate — EPSS is 5.0%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (2)
- from 0, < 1.22.4-2
- from 0, < 1.22.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |