Description
Path Traversal in GitHub repository gruntjs/grunt prior to 1.5.2.
References (3)
Core 3
Core References
Mailing List mailing-list
https://lists.debian.org/debian-lts-announce/2023/04/msg00008.html
Patch, Third Party Advisory
https://github.com/gruntjs/grunt/commit/aad3d4521c3098fb255fb2db8f2e1d691a033665
Exploit, Patch, Third Party Advisory
https://huntr.dev/bounties/f55315e9-9f6d-4dbb-8c40-bae50c1ae92b
Scores
CVSS v3
5.5
EPSS
0.0010
EPSS Percentile
27.2%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Details
CWE
CWE-22
Status
published
Products (2)
gruntjs/grunt
< 1.5.2
npm/grunt
0 - 1.5.2npm
Published
Apr 12, 2022
Tracked Since
Feb 18, 2026