OSV 1.4.0 · github-reviewed · 修改于 2021-04-13 23:32
发布时间
2021-04-13 23:32
GitHub 审查时间
2021-04-01 07:13
NVD 发布时间
2020-02-07 00:15
源文件
advisories/github-reviewed/2021/04/GHSA-xmxh-g7wj-8m4m/GHSA-xmxh-g7wj-8m4m.json
npm package curling before version 1.1.0 is vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.