VDB
Sign up
HIGH7.1

GHSA-m5pj-vjjf-4m3h

Arbitrary Code Execution in grunt

Quick fix

GHSA-m5pj-vjjf-4m3h — grunt: upgrade to the fixed version with the command below.

npm install grunt@1.3.0

Details

The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/grunt
Introduced in: 0Fixed in: 1.3.0
Fixnpm install grunt@1.3.0

References