CVE-2019-10789
9.8
CRITICAL · CVSS 3.1 · EPSS 4.9% (pctl 92)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.87% — more likely to be exploited than 92% of all CVEs |
| Weakness | CWE-78 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2020-02-06 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| curling project | curling |
References
- https://github.com/hgarcia/curling/blob/e861d625c074679a2931bcf4ce8da0afa8162c53/lib/curl-transport.js#L56
- https://snyk.io/vuln/SNYK-JS-CURLING-546484
- https://github.com/hgarcia/curling/blob/e861d625c074679a2931bcf4ce8da0afa8162c53/lib/curl-transport.js#L56
- https://snyk.io/vuln/SNYK-JS-CURLING-546484
→ the Explorer · watch your stack · NVD