hgarcia/curling

hgarcia/curling

Releases0
Stars2
A node wrapper for curl with a very simple api.

CVE History

CVEPublishedCVSS v3CVSS v2
9.8 CRITICAL10 HIGH

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.