Vulnerabilities
CVE-2026-24910 - Bun Trusted Dependencies Spoofing Vulnerability
CVE ID : CVE-2026-24910 Published : Jan. 27, 2026, 11:15 p.m. | 55 minutes ago Description : In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a matching name (for file, link, git, or github). Severity: 5.9 | MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...