{"api_version":"v1","generated_at":"2026-10-08T08:00:00+00:00","product":{"cve_count":2,"evidence_gap_note":"This CVE identity is linked to an existing Lifecycle product history.","id":"security:cve-yarnpkg-yarn-a5985323fbe7","lifecycle_state":"covered","linked_lifecycle_url":"https://lifecycle.blacktree.nl/targets/yarn","name":"Yarn","next_cursor":null,"observations":[{"affected":"1.22.0; 1.22.1; 1.22.2; 1.22.3; 1.22.4; 1.22.5; 1.22.6; 1.22.7","affected_versions_present":true,"cve_id":"CVE-2025-9308","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-9308","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-08-21T17:32:14.661Z","patch_url":"","primary_source":"","published":"2025-08-21T16:02:12.172Z"},{"affected":"1.22.0; 1.22.1; 1.22.2; 1.22.3; 1.22.4; 1.22.5; 1.22.6; 1.22.7","affected_versions_present":true,"cve_id":"CVE-2025-8262","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-8262","fixed":"An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.","last_modified":"2025-07-28T17:16:45.501Z","patch_url":"https://github.com/yarnpkg/yarn/pull/9199/commits/97731871e674bf93bcbf29e9d3258da8685f3076","primary_source":"","published":"2025-07-28T07:02:05.616Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"yarnpkg"}}
