Having read through the CVE, it appears to involve making a request to a hostile server with an intentionally restrictive set of commandline options, so it's really mainly a risk for things people can do to you if they can make you run arbitrary curl commands