Search/CVE-2018-12556
CVE — Medium

CVE-2018-12556

The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.

CVSS v3.1
5.9 MEDIUM
EPSS
1.77%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 7, 2026
0.00pp
1.77% → 1.77% over 7 tracked changes
CVSS v3.1 Detail
Attack VectorNETWORK
Attack ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
ScopeUNCHANGED
ConfidentialityNONE
IntegrityHIGH
AvailabilityNONE
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Connections
2 relationships
Timeline
disclosure → media coverage
May 16, 2019
Disclosure — published as a CVE record. · last revised by NVD Nov 21, 2024