Vlad Filippov

2 exploits Active since Sep 2020
CVE-2020-7729 WRITEUP HIGH WRITEUP
grunt < 1.3.0 - Arbitrary Code Execution via Insecure YAML Deserialization
The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.
CVSS 7.1
CVE-2022-0436 WRITEUP MEDIUM WRITEUP
gruntjs/grunt <1.5.2 - Path Traversal
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
CVSS 5.5