CVE-2019-10789

CRITICAL9.8EPSS 8.3%

OS Command Injection in curling

Published: 4/13/2021Modified: 11/8/2023
Also known as:GHSA-xmxh-g7wj-8m4m

Description

npm package `curling` before version 1.1.0 is vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (3)