CVE-2026-24910 - Bun Trusted Dependencies Spoofing Vulnerability
CVE ID : CVE-2026-24910
Published : Jan. 27, 2026, 11:15 p.m. | 1 hour, 43 minutes ago
Description : In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Jan. 27, 2026, 11:15 p.m. | 1 hour, 43 minutes ago
Description : In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).
Severity: 5.9 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...