Lucene search

K
osvGoogleOSV:GHSA-XMXH-G7WJ-8M4M
HistoryApr 13, 2021 - 3:32 p.m.

OS Command Injection in curling

2021-04-1315:32:26
Google
osv.dev
6
npm
package
curling
version
vulnerability
command injection
run function
users
sanitization

EPSS

0.268

Percentile

96.8%

npm package curling before version 1.1.0 is vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.

EPSS

0.268

Percentile

96.8%

Related for OSV:GHSA-XMXH-G7WJ-8M4M