Critical severity9.8NVD Advisory· Published May 7, 2020· Updated Jun 17, 2026
CVE-2020-7646
CVE-2020-7646
Description
curlrequest through 1.0.1 allows reading any file by populating the file parameter with user input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
curlrequestnpm | <= 1.0.1 | — |
Affected products
3- cpe:2.3:a:curlrequest_project:curlrequest:*:*:*:*:*:node.js:*:*Range: <=1.0.1
- curlrequest/curlrequestdescription
Patches
Vulnerability mechanics
References
5- snyk.io/vuln/SNYK-JS-CURLREQUEST-568274nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-m8xj-5v73-3hh8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2020-7646ghsaADVISORY
- github.com/node-js-libs/curlrequest/blob/master/index.jsghsaWEB
- github.com/node-js-libs/curlrequest/blob/master/index.jsnvd
News mentions
0No linked articles in our index yet.