Executive brief
grunt-images is a Node.js build tool plugin that downloads executable resources needed for image processing tasks. The package downloads these executables over unencrypted HTTP, allowing an attacker positioned on the network (such as on a compromised WiFi network or at an ISP level) to intercept and replace the executable with malicious code, leading to arbitrary code execution during the build process.
Technical details
The vulnerability is a missing encryption / insecure transport issue (CWE-311, CWE-269) where grunt-images downloads an executable over unencrypted HTTP instead of HTTPS. An attacker with a privileged network position (MITM capability) can intercept the HTTP response and replace the executable with a malicious variant, achieving remote code execution on the system running the build tool. The attack requires network-level access but no authentication, user interaction, or special privileges. No patch has been released since the package last received updates in 2013; the recommendation is to discontinue use of this package in favor of maintained alternatives.
Affected products
- npm grunt-images ≤ 0.2.1
Timeline
- 2018-08-15: disclosed
- other: Package unmaintained since 2013; no patch available