<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
<channel>
  <title>CVE Daily – Grunt</title>
  <link>https://cvedaily.com/pages/tags/grunt.html</link>
  <atom:link href="https://cvedaily.com/feed-tags/grunt.xml" rel="self" type="application/rss+xml"/>
  <description>CVE Daily – Grunt</description>
  <language>en</language>
  <lastBuildDate>Wed, 03 Jun 2026 21:27:07 +0000</lastBuildDate>
  <item>
    <title>[Medium] CVE-2024-49939 – In the Linux kernel, the following vulnerability has been resolved:

wifi: rtw89...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2024-49939</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2024-49939</guid>
    <pubDate>Mon, 21 Oct 2024 18:15:15 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2024-49939</strong></p>
  <p>In the Linux kernel, the following vulnerability has been resolved:  wifi: rtw89: avoid to add interface to list twice when SER  If SER L2 occurs during the WoWLAN resume flow, the add interface flow is triggered by ieee80211_reconfig(). However, due to rtw89_wow_resume() return failure, it will cause the add interface flow to be executed again, resulting in a double add list and causing a kernel…</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> N/A</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2024-49939">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Critical] CVE-2022-37602 – Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key ...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-37602</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-37602</guid>
    <pubDate>Fri, 14 Oct 2022 11:15:09 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk critical">Critical</span> CVE-2022-37602</strong></p>
  <p>Prototype pollution vulnerability in karma-runner grunt-karma 4.0.1 via the key variable in grunt-karma.js.</p>
  <p><strong>CVSS:</strong> 9.8 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-37602">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2020-7641 – This affects all versions of package grunt-util-property. The function call coul...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7641</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7641</guid>
    <pubDate>Sun, 17 Jul 2022 09:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2020-7641</strong></p>
  <p>This affects all versions of package grunt-util-property. The function call could be tricked into adding or modifying properties of Object.prototype using a __proto__ payload.</p>
  <p><strong>CVSS:</strong> 4.0 · <strong>CWE:</strong> CWE-1321</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7641">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2022-1537 – file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leadin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-1537</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-1537</guid>
    <pubDate>Tue, 10 May 2022 14:15:08 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2022-1537</strong></p>
  <p>file.copy operations in GruntJS are vulnerable to a TOCTOU race condition leading to arbitrary file write in GitHub repository gruntjs/grunt prior to 1.5.3. This vulnerability is capable of arbitrary file writes which can lead to local privilege escalation to the GruntJS user if a lower-privileged user has write access to both source and destination directories as the lower-privileged user can cr…</p>
  <p><strong>CVSS:</strong> 7.0 · <strong>CWE:</strong> CWE-367</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-1537">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[Medium] CVE-2022-0436 – Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2022-0436</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2022-0436</guid>
    <pubDate>Tue, 12 Apr 2022 21:15:07 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk medium">Medium</span> CVE-2022-0436</strong></p>
  <p>Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.</p>
  <p><strong>CVSS:</strong> 5.5 · <strong>CWE:</strong> CWE-22</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2022-0436">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2020-7729 – The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2020-7729</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2020-7729</guid>
    <pubDate>Thu, 03 Sep 2020 09:15:10 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2020-7729</strong></p>
  <p>The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.</p>
  <p><strong>CVSS:</strong> 7.1 · <strong>CWE:</strong> CWE-1188</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2020-7729">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10645 – grunt-images is a grunt plugin for processing images. grunt-images downloads bin...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10645</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10645</guid>
    <pubDate>Mon, 04 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10645</strong></p>
  <p>grunt-images is a grunt plugin for processing images. grunt-images downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10645">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10636 – grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads bi...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10636</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10636</guid>
    <pubDate>Mon, 04 Jun 2018 16:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10636</strong></p>
  <p>grunt-ccompiler is a Closure Compiler Grunt Plugin. grunt-ccompiler downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10636">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10606 – grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt gru...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10606</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10606</guid>
    <pubDate>Fri, 01 Jun 2018 18:29:01 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10606</strong></p>
  <p>grunt-webdriver-qunit is a grunt plugin to run qunit with webdriver in grunt grunt-webdriver-qunit downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary if the attacker is on the network or positioned in between the user and the remote server.</p>
  <p><strong>CVSS:</strong> 8.1 · <strong>CWE:</strong> CWE-311</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10606">View on NVD</a></p>
]]>
    </description>
  </item>
  <item>
    <title>[High] CVE-2016-10526 – A common setup to deploy to gh-pages on every commit via a CI system is to expos...</title>
    <link>https://nvd.nist.gov/vuln/detail/CVE-2016-10526</link>
    <guid isPermaLink="true">https://nvd.nist.gov/vuln/detail/CVE-2016-10526</guid>
    <pubDate>Thu, 31 May 2018 20:29:00 +0000</pubDate>
    <description>
<![CDATA[
  <p><strong><span class="badge risk high">High</span> CVE-2016-10526</strong></p>
  <p>A common setup to deploy to gh-pages on every commit via a CI system is to expose a github token to ENV and to use it directly in the auth part of the url. In module versions < 0.9.1 the auth portion of the url is outputted as part of the grunt tasks logging function. If this output is publicly available then the credentials should be considered compromised.</p>
  <p><strong>CVSS:</strong> 8.6 · <strong>CWE:</strong> CWE-391</p>
  <p><a href="https://nvd.nist.gov/vuln/detail/CVE-2016-10526">View on NVD</a></p>
]]>
    </description>
  </item>
</channel>
</rss>
