Junglewise Threat Intelligence

CVE-2016-10645: grunt-images insecure HTTP download of executable

CVE-2016-10645 · Severity: low · CVSS 3 · Published 2018-08-15

Vendors: npm.

Executive brief

grunt-images is a Node.js build tool plugin that downloads executable resources needed for image processing tasks. The package downloads these executables over unencrypted HTTP, allowing an attacker positioned on the network (such as on a compromised WiFi network or at an ISP level) to intercept and replace the executable with malicious code, leading to arbitrary code execution during the build process.

Technical details

The vulnerability is a missing encryption / insecure transport issue (CWE-311, CWE-269) where grunt-images downloads an executable over unencrypted HTTP instead of HTTPS. An attacker with a privileged network position (MITM capability) can intercept the HTTP response and replace the executable with a malicious variant, achieving remote code execution on the system running the build tool. The attack requires network-level access but no authentication, user interaction, or special privileges. No patch has been released since the package last received updates in 2013; the recommendation is to discontinue use of this package in favor of maintained alternatives.

Affected products

  • npm grunt-images ≤ 0.2.1

Timeline

  • 2018-08-15: disclosed
  • other: Package unmaintained since 2013; no patch available