In Bun before 1.3.5, the default trusted dependencies list (aka trust allow list) can be spoofed by a non-npm package in the case of a…
mitre·CWE-348·Published 2026-01-27