CVEs (3)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which ca...Show more |
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2. |
3Canonical DebianGruntjs3Debian Linux GruntUbuntu LinuxJun 17, 2026 Sep 3, 2020 N/A· v4 7.1 HIGH· v3 4.6 MEDIUM· v2 The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML. |