QID 982761
QID 982761: Nodejs (npm) Security Update for curling (GHSA-xmxh-g7wj-8m4m)
npm package `curling` before version 1.1.0 is vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-xmxh-g7wj-8m4m for updates pertaining to this vulnerability.
Vendor References
- GHSA-xmxh-g7wj-8m4m -
github.com/advisories/GHSA-xmxh-g7wj-8m4m
CVEs related to QID 982761
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-xmxh-g7wj-8m4m | curling |
|