StackRadar

CVE-2021-4435

High

Advisory

Published 4 Feb 2024In the index since 6 Sept 2026
Severity
High
worst across findings
CVSS
7.7
base score, highest
EPSS
0.003
23rd percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
130
of 17,787 indexed, latest versions
Container images
133
deployed by those charts
Fix available
1 of 1
affected package

Yarn untrusted search path vulnerability

Carried by container images the latest versions of 130 of 17,787 indexed charts deploy, on 133 images.

Affected packageAffected versionsFixed inImages
yarnnpm0.27.5, 1.3.2, 1.5.1, 1.7.0+11 more1.22.13133
OSV records
GHSA-mpwj-fcr6-x34c

Charts affected

130 by stars
ChartLatestAffected imagesRadar Score
iotmmontesVerified publisher0.3.24 of 7See more

iot mmontes 0.3.2

4 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ghcr.io/mmontes11/iot-back:v3.11.096683c54ae65
yarn@1.22.5
1.22.13
ghcr.io/mmontes11/iot-biot:v3.11.033f7976b26a8
yarn@1.22.5
1.22.13
ghcr.io/mmontes11/iot-thing:v3.11.0542e91e8499c
yarn@1.22.5
1.22.13
ghcr.io/mmontes11/iot-worker:v3.11.0491bb243f555
yarn@1.22.5
1.22.13

Open the chart page →

10,608
account-lookup-servicemojaloop13.0.02 of 4See more

account-lookup-service mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13

Open the chart page →

11,734
account-lookup-service-adminmojaloop13.0.02 of 4See more

account-lookup-service-admin mojaloop 13.0.0

2 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13

Open the chart page →

11,734
admin-api-svcmojaloop12.0.02 of 4See more

admin-api-svc mojaloop 12.0.0

2 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/central-ledger:v13.14.01abc8a7aa71c
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13

Open the chart page →

12,147
fspiop-transfer-api-svcmojaloop12.0.12 of 3See more

fspiop-transfer-api-svc mojaloop 12.0.1

2 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
yarn@1.22.0
1.22.13

Open the chart page →

11,518
mojaloopmojaloop14.0.04 of 6See more

mojaloop mojaloop 14.0.0

4 of the 6 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
mojaloop/central-ledger:v13.14.01abc8a7aa71c
yarn@1.22.0
1.22.13
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
yarn@1.22.0
1.22.13

Open the chart page →

19,265
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
yarn@1.22.4
1.22.13

Open the chart page →

6,684
smilencsaVerified publisher1.1.02 of 23See more

smile ncsa 1.1.0

2 of the 23 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
socialmediamacroscope/smile_graphql:0.3.1c5095e94bc65
yarn@1.22.10
1.22.13
socialmediamacroscope/smile_server:0.3.31a528c794270
yarn@1.22.10
1.22.13

Open the chart page →

109,485
node-appnode-app-charts0.1.01 of 1See more

node-app node-app-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
eameti/node-app:latestf36642affa86
yarn@1.22.5
1.22.13

Open the chart page →

1,444
example-dev-toolsnoygal0.2.81 of 3See more

example-dev-tools noygal 0.2.8

1 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
linuxserver/codimd:latestb801bbcf6386
yarn@1.22.5
1.22.13

Open the chart page →

27,486
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
yarn@1.22.4
1.22.13

Open the chart page →

36,230
hive-selfservice-ui-nodeory0.1.01 of 1See more

hive-selfservice-ui-node ory 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
oryd/hive-selfservice-ui-node:v0.0.426347ef0a2de
yarn@1.19.1
1.22.13

Open the chart page →

1,986
myappp4-helm0.1.02 of 6See more

myapp p4-helm 0.1.0

2 of the 6 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
yarn@1.22.0
1.22.13
fjvela/urjc-fjvela-server:1.0.53c840aebce22
yarn@1.22.0
1.22.13

Open the chart page →

19,725
codimdphntom0.1.121 of 3See more

codimd phntom 0.1.12

1 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
phntom/codimd:2.4.31b9aafbb62e6
yarn@1.22.5
1.22.13

Open the chart page →

6,524
practica-helmpractica-helm0.1.01 of 7See more

practica-helm practica-helm 0.1.0

1 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
slagattollas/server-practica:latest6dd8ead8e2b1
yarn@1.22.5
1.22.13

Open the chart page →

28,495
bookinforgnu1.0.01 of 7See more

bookinfo rgnu 1.0.0

1 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
yarn@1.15.2
1.22.13

Open the chart page →

20,480
istio-bookinforgnu1.0.21 of 7See more

istio-bookinfo rgnu 1.0.2

1 of the 7 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
yarn@1.15.2
1.22.13

Open the chart page →

20,480
parkingsikalabs0.1.01 of 1See more

parking sikalabs 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ondrejsika/parking:latestb1fd497416c8
yarn@1.22.5
1.22.13

Open the chart page →

3,696
first-appsimple-helm-chart0.1.01 of 1See more

first-app simple-helm-chart 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
leeyoongti/first-app:1.0.021d66cb76352
yarn@1.22.5
1.22.13

Open the chart page →

2,154
logsmo-helm-chart6.0.01 of 6See more

log smo-helm-chart 6.0.0

1 of the 6 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yarn@1.19.1
1.22.13

Open the chart page →

29,244
pombasmo-helm-chart6.0.01 of 17See more

pomba smo-helm-chart 6.0.0

1 of the 17 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yarn@1.19.1
1.22.13

Open the chart page →

29,244
pwssoketi0.2.41 of 1See more

pws soketi 0.2.4

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
quay.io/soketi/pws:0.8-16-alpine399d2e6b10ef
yarn@1.22.5
1.22.13

Open the chart page →

3,228
pachydermstatcan0.5.11 of 4See more

pachyderm statcan 0.5.1

1 of the 4 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
pachyderm/grpc-proxy:0.4.92b27f41d4d02
yarn@1.15.2
1.22.13

Open the chart page →

4,967
dashkioskt3n2.0.01 of 1See more

dashkiosk t3n 2.0.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
quay.io/t3n/dashkiosk:v2.7.8c973e166a5dc
yarn@1.21.1
1.22.13

Open the chart page →

3,827
pock-helm-charttinote-chart0.1.01 of 3See more

pock-helm-chart tinote-chart 0.1.0

1 of the 3 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
denisshav/backend:latest4cc8dc5a4499
yarn@1.22.5
1.22.13

Open the chart page →

6,881
kubernetes-external-secretstrozz6.3.01 of 1See more

kubernetes-external-secrets trozz 6.3.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ghcr.io/external-secrets/kubernetes-external-secrets:6.3.0eab9bd0b6986
yarn@1.22.5
1.22.13

Open the chart page →

2,838
queryservice-gatewaywbstack0.2.01 of 1See more

queryservice-gateway wbstack 0.2.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ghcr.io/wbstack/queryservice-gateway:2.2ab8e2f583e56
yarn@1.22.5
1.22.13

Open the chart page →

2,559
cadencewenerme0.23.01 of 5See more

cadence wenerme 0.23.0

1 of the 5 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
ubercadence/web:v3.29.58564a5b44a6d
yarn@1.22.5
1.22.13

Open the chart page →

10,127
temporalwenerme0.15.11 of 13See more

temporal wenerme 0.15.1

1 of the 13 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
temporalio/web:1.14.033cfa863d8ce
yarn@1.22.5
1.22.13

Open the chart page →

22,665
helloworldyotron-helm-charts0.1.01 of 1See more

helloworld yotron-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2021-4435.

Container imageDigestPackageFixed in
a5hut0sh/helloworld:1.02ae77620e616
yarn@1.12.3
1.22.13

Open the chart page →

1,309

Container images carrying it

133 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
mojaloop/event-sidecar:v11.0.189b8ab71b74b
yarn@1.22.0
1.22.13
5
oscarsotosanchez/server:v1.06e2e1279126b
yarn@1.22.5
1.22.13
4
frankescobar/allure-docker-service-ui:7.0.3:latest4ebd8b4ef340
yarn@1.22.4
1.22.13
3
mojaloop/account-lookup-service:v11.8.0b06d3287ea82
yarn@1.22.0
1.22.13
3
pantsel/konga:latestc8172b75607d
yarn@1.22.4
1.22.13
3
fjvela/urjc-fjvela-external-service:1.0.1a8ebe5ca13fc
yarn@1.22.0
1.22.13
2
fjvela/urjc-fjvela-server:1.0.53c840aebce22
yarn@1.22.0
1.22.13
2
governify/assets-manager:v1.4.12987672448c7
yarn@1.22.4
1.22.13
2
governify/director:v1.4.0608c6940bb98
yarn@1.22.4
1.22.13
2
governify/registry:v3.4.0d3f37f4f8168
yarn@1.22.4
1.22.13
2
governify/render:v2.2.0daeca1ce28e6
yarn@1.22.4
1.22.13
2
governify/reporter:v2.2.038595913458f
yarn@1.22.4
1.22.13
2
istio/examples-bookinfo-ratings-v1:1.15.009b9d6958a13
yarn@1.16.0
1.22.13
2
istio/examples-bookinfo-ratings-v1:1.14.0eb0f1a725ca8
yarn@1.15.2
1.22.13
2
jupyterhub/configurable-http-proxy:4.5.08ced0a2f8073
yarn@1.22.5
1.22.13
2
koenkk/zigbee2mqtt:1.19.15f9129b1ffbc
yarn@1.22.5
1.22.13
2
martinaif/backstage-k8s-demo-backend:test143bc40a3da0e
yarn@1.22.4
1.22.13
2
mojaloop/central-ledger:v13.14.01abc8a7aa71c
yarn@1.22.0
1.22.13
2
mojaloop/ml-api-adapter:v11.1.6fb71d233c742
yarn@1.22.0
1.22.13
2
statsd/statsd:v0.8.6dab129e74c25
yarn@1.13.0
1.22.13
2
taskrabbit/elasticsearch-dump:latestc967fe68b9c7
yarn@1.19.1
1.22.13
2
a5hut0sh/helloworld:1.02ae77620e616
yarn@1.12.3
1.22.13
1
adrianberger/fluxcd-webui:latest76848c0d2780
yarn@1.22.5
1.22.13
1
aolde/bredbandskollen-prometheus-exporter:1.0.2dc61ee713720
yarn@1.22.5
1.22.13
1
aureliengasser/http-folder:1.1.111c4318c2571
yarn@1.21.1
1.22.13
1
bastilimbach/docker-magicmirror:v2.15.041b0835ab31e
yarn@1.22.5
1.22.13
1
billimek/node-influx-uptimerobot:latest5814f0bcf5ba
yarn@1.7.0
1.22.13
1
carbonetes/carbonetes-analyzer:1.0.31b9b93c9a37f
yarn@1.22.5
1.22.13
1
cnieg/maildev:v1.1.998ee05668915
yarn@1.22.4
1.22.13
1
codercom/code-server:3.10.247605610ad8d
yarn@1.22.10
1.22.13
1
conduction/conduction-ui-app:devd591f5e6f2a9
yarn@1.22.4
1.22.13
1
davidvmar/urjc-davidvmar-external-service:1.0.02a68e9ac7f09
yarn@1.22.0
1.22.13
1
davidvmar/urjc-davidvmar-server:1.0.05663f5b24615
yarn@1.22.0
1.22.13
1
decayofmind/hubot:3.3.21e18e92fe694
yarn@1.16.0
1.22.13
1
denisshav/backend:latest4cc8dc5a4499
yarn@1.22.5
1.22.13
1
devspacecloud/ui:0.3.3deef55ff29a7
yarn@1.15.2
1.22.13
1
eameti/node-app:latestf36642affa86
yarn@1.22.5
1.22.13
1
electerious/ackee:3.2.05e7173fa321c
yarn@1.22.5
1.22.13
1
ethersphere/bzz-token-service:latest7624f11a72ad
yarn@1.22.5
1.22.13
1
felddy/foundryvtt:0.8.36c5d90b90349
yarn@1.22.5
1.22.13
1
fiware/iotagent-ul:1.14.0fe11f55a926d
yarn@1.21.1
1.22.13
1
flagsmith/flagsmith-frontend:v2.6.0df02a29e8b0c
yarn@1.22.5
1.22.13
1
frappe/frappe-socketio:v13.4.12095767a9e82
yarn@1.22.5
1.22.13
1
halkeye/gitter-slack-bridge:v2.0.153eb2b3cd4cb
yarn@1.22.0
1.22.13
1
halkeye/hubot:latest9764d2202130
yarn@1.22.5
1.22.13
1
halkeye/irslackd:latest7638bfba70b0
yarn@1.12.3
1.22.13
1
hhaluk/crypto-watchdog:0.4.0a6555953d941
yarn@1.21.1
1.22.13
1
i4trust/pdc-portal:2.0.03e77858e1219
yarn@1.22.5
1.22.13
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
yarn@1.13.0
1.22.13
1
ibmcom/microclimate-file-watcher:latestab3fd1fdfa18
yarn@1.5.1
1.22.13
1

syft 1.42.1 · advisories as of 15 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.