CVE-2026-24910: Bun

Medium severity, CVSS 5.9. EPSS: 0.1% chance of exploitation in the next 30 days.

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).

Affected products

  • Bun Bun: before 1.3.5 (fixed in 1.3.5)

Published 2026-01-27. Last modified 2026-06-17.