CVE-2019-10789

Publication date

2020-02-06 15:58:53

Family

snyk

State

PUBLISHED

Description

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.