{"id":"GHSA-xmxh-g7wj-8m4m","summary":"OS Command Injection in curling","details":"npm package `curling` before version 1.1.0 is vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.","aliases":["CVE-2019-10789"],"modified":"2023-11-08T04:00:57.030685Z","published":"2021-04-13T15:32:26Z","database_specific":{"nvd_published_at":"2020-02-06T16:15:00Z","cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2021-03-31T23:13:03Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-10789"},{"type":"WEB","url":"https://github.com/hgarcia/curling/blob/e861d625c074679a2931bcf4ce8da0afa8162c53/lib/curl-transport.js#L56"},{"type":"WEB","url":"https://snyk.io/vuln/SNYK-JS-CURLING-546484"}],"affected":[{"package":{"name":"curling","ecosystem":"npm","purl":"pkg:npm/curling"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.1.0"}]}],"database_specific":{"last_known_affected_version_range":"\u003c= 1.0.0","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2021/04/GHSA-xmxh-g7wj-8m4m/GHSA-xmxh-g7wj-8m4m.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}