PT-2026-5032 · Bun · Bun

Orenyomtov

·

Published

2026-01-27

·

Updated

2026-01-28

·

CVE-2026-24910

CVSS v3.1

5.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Bun versions prior to 1.3.5
Description The default trusted dependencies list in Bun can be manipulated by a non-npm package if the package name matches an existing trusted dependency. This affects dependencies installed via file, link, or git/github sources.
Recommendations Update to version 1.3.5 or later.

Fix

Weakness Enumeration

Related Identifiers

CVE-2026-24910

Affected Products

Bun