Lucene search

K
osvGoogleOSV:CVE-2020-7729
HistorySep 03, 2020 - 9:15 a.m.

CVE-2020-7729

2020-09-0309:15:10
Google
osv.dev
7

AI Score

7

Confidence

Low

EPSS

0.009

Percentile

82.3%

The package grunt before 1.3.0 are vulnerable to Arbitrary Code Execution due to the default usage of the function load() instead of its secure replacement safeLoad() of the package js-yaml inside grunt.file.readYAML.

AI Score

7

Confidence

Low

EPSS

0.009

Percentile

82.3%