« Back to list

Gruntjs

Gruntjs Grunt: vulnerabilities and CVEs

Gruntjs Grunt has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs3
Last 12 months0
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2022-1537High (7)0.30%—May 10, 2022
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which…
CVE-2022-0436Medium (5.5)0.57%—Apr 12, 2022
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
CVE-2020-7729High (7.1)2.3%—Sep 3, 2020
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.