CVE-2019-10789: OS Command Injection in curling

Severity: Critical

CVSS Score: 9.8

All versions of curling.js are vulnerable to Command Injection via the run function. The command argument can be controlled by users without any sanitization.