# sonatype-2024-0036

everything, no-one-left-behind - Potentially Unwanted Application(s) [PUAs]

Published Jan 4, 2024

[OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-27586.json) [bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/)

## CVSS Score
High

### 7.5

## Security Details
### Components Impacted

#### Sonatype Research

### sonatype-2024-0036 Security Details

- **CVE ID:** sonatype-2024-0036
- **CVE Description:** everything, no-one-left-behind - Potentially Unwanted Application(s) [PUAs]
- **Published:** Jan 4, 2024
- **CVSS Score & Severity:** 7.5 High
- **CVSS Vector:** CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- **EPSS Score:** 0%
- **Malware:** malware
- **KEV Status:** Not in KEV Catalog: No known exploits

### Affected Ecosystems

### Source
Sonatype

### References
- [OSV](https://osv-vulnerabilities.storage.googleapis.com/npm/MAL-2025-27586.json)
- [bleepingcomputer.com](https://www.bleepingcomputer.com/news/security/everything-blocks-devs-from-removing-their-own-npm-packages/)
