Executive brief
Grunt is a task automation tool widely used in JavaScript development workflows to automate build processes. A race condition in its file copy operations allows a lower-privileged attacker to write arbitrary files by exploiting a time-of-check-time-of-use (TOCTOU) window, potentially leading to privilege escalation if the tool runs with elevated permissions.
Technical details
A TOCTOU (time-of-check-time-of-use) race condition exists in Grunt's file.copy operations (CWE-367) prior to version 1.5.3. An attacker with write access to both source and destination directories can exploit the vulnerability by creating a symbolic link between the check and use phases, redirecting file writes to arbitrary locations. This can achieve arbitrary file write with the privileges of the Grunt process, enabling local privilege escalation (e.g., modifying .bashrc or /etc/shadow if Grunt runs as root). The vulnerability requires local access and the ability to write to directories involved in the copy operation. A patch is available in Grunt 1.5.3 and later.
Affected products
- Grunt Grunt prior to 1.5.3
Timeline
- 2022-05-11: disclosed
- 2022: patched: Fixed in version 1.5.3