CVE-2022-1537 is a Time-of-Check to Time-of-Use (TOCTOU) race condition vulnerability affecting file.copy operations in GruntJS versions prior to 1.5.3. This flaw allows for arbitrary file writes, potentially leading to local privilege escalation if a lower-privileged user can manipulate both source and destination directories. The vulnerability has a CVSS score of 7.0 (High), indicating a high impact on confidentiality, integrity, and availability, with a local attack vector and high attack complexity. Successful exploitation could allow an attacker to gain privileges of the GruntJS user, even replacing critical system files if the GruntJS user has root privileges. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available. Community discussion and media coverage for this CVE are minimal, suggesting low public awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.3CPE matchmatch criteria | cpe:2.3:a:gruntjs:grunt:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.