CVE-2019-15608: Yarnpkg Yarn

Medium severity, CVSS 5.9. EPSS: 1.8% chance of exploitation in the next 30 days.

The package integrity validation in yarn < 1.19.0 contains a TOCTOU vulnerability where the hash is computed before writing a package to cache. It's not computed again when reading from the cache. This may lead to a cache pollution attack.

Affected products

  • Yarnpkg Yarn: before 1.19.0 (fixed in 1.19.0)

Published 2020-03-15. Last modified 2026-06-17.