Executive brief
Yarn, a popular JavaScript package manager, contains a path traversal vulnerability that allows attackers to write arbitrary files to any location on a system during package installation. By crafting a malicious package, an attacker can trick users into installing it, potentially leading to code execution or system compromise. This vulnerability affects versions 1.21.1 and earlier.
Technical details
The vulnerability is a path traversal (CWE-22) flaw in Yarn's file handling during package fetching and installation. An attacker can craft a malicious package that, when installed via yarn install, writes files outside the intended package directory by exploiting insufficient path validation. The attack requires user interaction (convincing a user to install the malicious package) but no authentication. Successful exploitation can lead to arbitrary file write on the filesystem and potentially arbitrary code execution, especially when postinstall scripts are enabled or when --ignore-scripts is not used. The vulnerability was patched in Yarn 1.22.0.
Affected products
- Yarn Yarn 1.21.1 and earlier
Timeline
- 2020-02-24: disclosed: Published on NVD
- 2020-01-31: patched: Fix merged into Yarn master branch; released in version 1.22.0