CVE-2019-10789
CRITICALcurling < 1.1.0 - OS Command Injection via Run Function
Title source: llmDescription
All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.
References (2)
Core 2
Core References
Exploit, Third Party Advisory x_refsource_misc
https://snyk.io/vuln/SNYK-JS-CURLING-546484
Exploit, Third Party Advisory x_refsource_misc
https://github.com/hgarcia/curling/blob/e861d625c074679a2931bcf4ce8da0afa8162c53/lib/curl-transport.js#L56
Scores
CVSS v3
9.8
EPSS
0.0487
EPSS Percentile
90.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-78
Status
published
Products (2)
curling_project/curling
npm/curling
0 - 1.1.0npm
Published
Feb 06, 2020
Tracked Since
Feb 18, 2026