CVE-2020-7626: karma-mojo enables OS Command Injection

Severity: Critical

CVSS Score: 9.8

karma-mojo through 1.0.1 is vulnerable to Command Injection. It allows execution of arbitrary commands via the config argument.