StackRadar

CVE-2021-4435

High

Advisory

Published 4 Feb 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
131
of 17,781 indexed, latest versions
Container images
134
deployed by those charts
Fix available
1 of 1
affected package

Yarn untrusted search path vulnerability

Carried by container images the latest versions of 131 of 17,781 indexed charts deploy, on 134 images.

Affected packageAffected versionsFixed inImages
yarnnpm0.27.5, 1.3.2, 1.5.1, 1.7.0+11 more1.22.13134
OSV records
GHSA-mpwj-fcr6-x34c

Charts affected

131 by stars
ChartLatestAffected imagesRadar Score
iotmmontesVerified publisher0.3.24 of 7See more

iot mmontes 0.3.2

4 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
yarn@1.22.5
1.22.13
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
yarn@1.22.5
1.22.13
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
yarn@1.22.5
1.22.13
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
yarn@1.22.5
1.22.13

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13

Open the chart page →

11,695
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13

Open the chart page →

11,695
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13

Open the chart page →

12,108
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
yarn@1.22.0
1.22.13

Open the chart page →

11,479
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
mojaloop/central-ledger:v13.14.01abc8a7aa71c
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
yarn@1.22.0
1.22.13

Open the chart page →

19,226
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
yarn@1.22.4
1.22.13

Open the chart page →

6,684
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
yarn@1.22.10
1.22.13
socialmediamacroscope/smile_server:0.3.31a528c794270
yarn@1.22.10
1.22.13

Open the chart page →

109,294
node-appnode-app-charts0.1.01 of 1See more

node-app node-app-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
eameti/node-app:latestf36642affa86
yarn@1.22.5
1.22.13

Open the chart page →

1,444
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
yarn@1.22.5
1.22.13

Open the chart page →

27,465
ferdi-serverobeoneVerified publisher1.0.31 of 2See more

ferdi-server obeone 1.0.3

1 of the 2 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
getferdi/ferdi-server:1.3.26e620b85afaa
yarn@1.22.5
1.22.13

Open the chart page →

1,866
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
yarn@1.22.4
1.22.13

Open the chart page →

36,215
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
yarn@1.19.1
1.22.13

Open the chart page →

1,986
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
yarn@1.22.0
1.22.13
fjvela/urjc-fjvela-server:1.0.53c840aebce22
yarn@1.22.0
1.22.13

Open the chart page →

19,720
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
yarn@1.22.5
1.22.13

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
yarn@1.22.5
1.22.13

Open the chart page →

28,484
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
yarn@1.15.2
1.22.13

Open the chart page →

20,462
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
yarn@1.15.2
1.22.13

Open the chart page →

20,462
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
yarn@1.22.5
1.22.13

Open the chart page →

3,696
first-appsimple-helm-chart0.1.01 of 1See more

first-app simple-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
leeyoongti/first-app:1.0.021d66cb76352
yarn@1.22.5
1.22.13

Open the chart page →

2,154
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yarn@1.19.1
1.22.13

Open the chart page →

29,220
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yarn@1.19.1
1.22.13

Open the chart page →

29,220
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
yarn@1.22.5
1.22.13

Open the chart page →

3,228
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
yarn@1.15.2
1.22.13

Open the chart page →

4,967
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
yarn@1.21.1
1.22.13

Open the chart page →

3,827
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
yarn@1.22.5
1.22.13

Open the chart page →

6,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
yarn@1.22.5
1.22.13

Open the chart page →

2,838
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
yarn@1.22.5
1.22.13

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
yarn@1.22.5
1.22.13

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
yarn@1.22.5
1.22.13

Open the chart page →

22,665
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
yarn@1.12.3
1.22.13

Open the chart page →

1,309

Container images carrying it

134 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
thelounge/thelounge:4.3.0-alpine0037aa258261
yarn@1.22.10
1.22.13
1
thelounge/thelounge:4.2.0-alpine639978459c3a
yarn@1.22.4
1.22.13
1
tooljet/tooljet-ce:v1.18.0c85a4720e42e
yarn@1.22.5
1.22.13
1
trufflesuite/ganache-cli:v6.12.2c062707f17f3
yarn@1.22.10
1.22.13
1
tvanro/prerender-alpine:6.4.06909015f0328
yarn@1.22.5
1.22.13
1
ubercadence/web:v3.29.58564a5b44a6d
yarn@1.22.5
1.22.13
1
willwill/kube-slack:v4.1.1d443017aae98
yarn@1.13.0
1.22.13
1
wiremind/scrapoxy:lateste7048929a676
yarn@1.22.4
1.22.13
1
zazuko/trifid:2.3.7054be137de70
yarn@1.22.5
1.22.13
1
zooz/predator:1.6f491d1f7a865
yarn@1.22.4
1.22.13
1
zwavejs/zwavejs2mqtt:5.0.215a6040fb468
yarn@1.22.5
1.22.13
1
gcr.io/google-samples/microservices-demo/currencyservice:v0.2.349d458a3650f
yarn@1.22.5
1.22.13
1
gcr.io/google-samples/microservices-demo/paymentservice:v0.2.36eb201217a8f
yarn@1.22.5
1.22.13
1
ghcr.io/ctron/streamsheets-base:2.4.00cf25ed621e2
yarn@1.22.10
1.22.13
1
ghcr.io/ctron/streamsheets-gateway:2.4.00635f17c9d2c
yarn@1.22.10
1.22.13
1
ghcr.io/ctron/streamsheets-service-graphs:2.4.0e34964e336c1
yarn@1.22.10
1.22.13
1
ghcr.io/ctron/streamsheets-service-machines:2.4.00c5a3398d1e4
yarn@1.22.10
1.22.13
1
ghcr.io/ctron/streamsheets-service-streams:2.4.08ba040e79ca0
yarn@1.22.10
1.22.13
1
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
yarn@1.22.5
1.22.13
1
ghcr.io/flaresolverr/flaresolverr:v1.2.896f8c08c0c1b
yarn@1.22.5
1.22.13
1
ghcr.io/leoquote/mergeable:latest451706815103
yarn@1.22.0
1.22.13
1
ghcr.io/mario-f/kubevis:v1.4.0763daf9caf8e
yarn@1.21.1
1.22.13
1
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
yarn@1.22.5
1.22.13
1
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
yarn@1.22.5
1.22.13
1
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
yarn@1.22.5
1.22.13
1
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
yarn@1.22.5
1.22.13
1
ghcr.io/sct/overseerr:1.26.1254d16af8f71
yarn@1.22.5
1.22.13
1
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
yarn@1.22.5
1.22.13
1
quay.io/ibmgaragecloud/developer-dashboard:v1.4.47a4b9fedc724
yarn@1.22.5
1.22.13
1
quay.io/ibmgaragecloud/nodejs:latest01c3b7acb301
yarn@1.22.4
1.22.13
1
quay.io/ibmgaragecloud/slack-notifications:latest041df93e2bac
yarn@1.22.5
1.22.13
1
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
yarn@1.22.5
1.22.13
1
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
yarn@1.21.1
1.22.13
1
registry.gitlab.com/infinitydon/registry/open5gs-webui:v2.2.2fda21b0a0344
yarn@1.21.1
1.22.13
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.