Curling Project maintains the curling library, a data transfer tool that is widely embedded in applications and systems across multiple domains, creating a deployment footprint that extends beyond its modest direct exposure. The observed vulnerability signal centers on OS command injection, reflecting the risks inherent to a tool that processes user-supplied URLs and invokes shell operations. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Curling Project over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10789CRITICAL All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization. | Feb 6, 2020 | 9.8 | 30 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Curling Project.
Media articles that mention a CVE ID that affects a product developed by Curling Project — matched by CVE ID, not by vendor name.