CVE-2026-24910 Details
Description
In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github).
A vulnerability in Bun versions prior to 1.3.5 allows a non-npm package to spoof the default trusted dependencies list, known as the trust allow list. This spoofing can occur if the package name matches one of the trusted names and is used in a file, link, git, or github dependency. As a result, the package can execute lifecycle scripts that would normally be restricted.
Users can update Bun to version 1.3.5 or later, where this vulnerability has been patched.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 27, 2026CISA-ADP
Assessed Jan 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bun.com/blog/bun-v1.3.5 | [email protected] | Release NotesVendor |
| https://www.koi.ai/blog/packagegate-6-zero-days-in-js-package-managers-but-npm-wont-act | [email protected] | BundleRemedyTechnical Analysis |
| https://www.scworld.com/news/six-javascript-zero-day-bugs-lead-to-fears-of-supply-chain-attack | [email protected] | Media Coverage |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-348 | Use of Less Trusted Source | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Bun | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 27, 2026 | New CVE Received | [email protected] |
Volerion