The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does not pin the signature to the yarn release key, which allows remote attackers to sign tampered yarn release packages with their own key.
Conclusion & alert: CVE-2018-12556 is rated Moderate Risk (42.6/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.34%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-03-17 | 0.37% | 0.34% | -0.03% |
| 2 | 2024-12-17 | 0.47% | 0.37% | -0.10% |
| 3 | 2024-11-15 | — | 0.47% | — |
Full EPSS history (8 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 5.9 | 3.0 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
ubuntu
|
medium | CVE-2018-12556 medium priority: Ubuntu including 1 source packages (node-yarnpkg), 19 status rows across 19 suites (bionic, cosmic, disco, eoan, focal, groovy, hirsute, impish, jammy, kinetic, lunar, mantic, noble, oracular, plucky, questing, trusty, upstream, xenial): ignored 10, needs-triage 5, DNE 4. | https://ubuntu.com/security/CVE-2018-12556 |
| URL | Tags |
|---|---|
| http://packetstormsecurity.com/files/152703/Johnny-You-Are-Fired.html | Third Party Advisory VDB Entry |
| http://seclists.org/fulldisclosure/2019/Apr/38 | Mailing List Third Party Advisory |
| https://github.com/RUB-NDS/Johnny-You-Are-Fired | Third Party Advisory |
| https://github.com/RUB-NDS/Johnny-You-Are-Fired/blob/master/paper/johnny-fired.pdf | Third Party Advisory |
| https://github.com/yarnpkg/website/commits/master | Third Party Advisory |
| https://www.openwall.com/lists/oss-security/2019/04/30/4 | Mailing List Third Party Advisory |