Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
npm/js-yaml — 3 CVEs · VulnScope
pkg:npm/
js-yaml
3 total CVEs
MEDIUM
2
✅ Check your installed version
Check
All known vulnerabilities
MEDIUM
5.3
CVE-2026-53550
JS-YAML: Quadratic-complexity DoS in merge key handling via repeated aliases
from 0, < 4.2.0
MEDIUM
5.3
CVE-2025-64718
js-yaml has prototype pollution in merge (<<)
>= 4.0.0, < 4.1.1
—
CVE-2013-4660
Deserialization Code Execution in js-yaml
from 0, < 2.0.5