CVE-2026-24910 | Teknoloji dünyasından en güncel haberleri ve güvenlikle ilgili gelişmeleri takip edin.

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file,…
Medium CVSS: 5.9

CVE-2026-24910

In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).
Vendor
-
Product
-
CWE
CWE-348
Yayın Tarihi
2026-01-27 23:15:50
Güncelleme
2026-01-29 16:31:35
Source Identifier
cve@mitre.org
KEV Date Added
-

Kategoriler

Referanslar