<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T19:42:07.063435+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bell-cve-2019-10773</id>
    <title>Withdrawn: BELL-CVE-2019-10773 — CVE-2019-10773 does not affect BellSoft software</title>
    <updated>2026-10-02T19:42:07.215908+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>
          <strong>Withdrawn by the publisher.</strong>
        </p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/bell-cve-2019-10773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/cnvd-2020-03727</id>
    <title>cnvd-2020-03727</title>
    <updated>2026-10-02T19:42:07.215952+00:00</updated>
    <content>cnvd-2020-03727</content>
    <link href="https://cve.radiocsirt.org/vuln/cnvd-2020-03727"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53935</id>
    <title>EUVD-2026-53935</title>
    <updated>2026-10-02T19:42:07.215969+00:00</updated>
    <content>EUVD-2026-53935</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53935"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10773</id>
    <title>fkie_cve-2019-10773</title>
    <updated>2026-10-02T19:42:07.215981+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-10773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-5xf4-f2fq-f69j</id>
    <title>GHSA-5xf4-f2fq-f69j — Yarn Improper link resolution before file access (Link Following)</title>
    <updated>2026-10-02T19:42:07.216010+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: yarn</p>
<p>In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-5xf4-f2fq-f69j"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-10773</id>
    <title>gsd-2019-10773</title>
    <updated>2026-10-02T19:42:07.216033+00:00</updated>
    <content>gsd-2019-10773</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-10773"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2020:0475</id>
    <title>RHSA-2020:0475 — Red Hat Security Advisory: Red Hat Quay v3.2.1 security update</title>
    <updated>2026-10-02T19:42:07.216044+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>nodejs-yarn: Install functionality can be abused to generate arbitrary symlinks</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2020:0475"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10773</id>
    <title>UBUNTU-CVE-2019-10773</title>
    <updated>2026-10-02T19:42:07.216062+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:20.04:LTS: node-yarnpkg, Ubuntu:22.04:LTS: node-yarnpkg</p>
<p>In Yarn before 1.21.1, the package install functionality can be abused to generate arbitrary symlinks on the host filesystem by using specially crafted "bin" keys. Existing files could be overwritten depending on the current user permission set.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2019-10773"/>
  </entry>
</feed>
