<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Grunt (High+Critical)</title>
  <link>https://cvedaily.com/pages/tags/grunt.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/grunt-severe.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Grunt (High+Critical)</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[Critical] CVE-2022-37602 – Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37602</guid>
    <pubDate>Fri, 14 Oct 2022 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37602</strong></p>
  <p>Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1537 – file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leadin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1537</guid>
    <pubDate>Tue, 10 May 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1537</strong></p>
  <p>file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can cr…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7729 – The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7729</guid>
    <pubDate>Thu, 03 Sep 2020 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7729</strong></p>
  <p>The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10645 – grunt-images is a grunt plugin for processing images. grunt-images downloads bin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10645</guid>
    <pubDate>Mon, 04 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10645</strong></p>
  <p>grunt-images is a grunt plugin for processing images. grunt-images downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10636 – grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10636</guid>
    <pubDate>Mon, 04 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10636</strong></p>
  <p>grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10606 – grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt gru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10606</guid>
    <pubDate>Fri, 01 Jun 2018 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10606</strong></p>
  <p>grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10526 – A common setup to deploy to gh-pages on every commit via a CI system is to expos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10526</guid>
    <pubDate>Thu, 31 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10526</strong></p>
  <p>A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10526">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
