Gruntjs
Gruntjs Grunt: vulnerabilities and CVEs
Gruntjs Grunt has 3 published vulnerabilities, 0 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months0
Critical0
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-1537 | High (7) | 0.30% | — | May 10, 2022 | file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which… |
| CVE-2022-0436 | Medium (5.5) | 0.57% | — | Apr 12, 2022 | Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2. |
| CVE-2020-7729 | High (7.1) | 2.3% | — | Sep 3, 2020 | The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |