Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/703415
Related Vulnerabilities
CVE-2019-5483 Vulnerability in npm package seneca
CVE-2018-14627 Vulnerability in maven package org.wildfly:wildfly-feature-pack
CVE-2020-1914 Vulnerability in npm package hermes-engine
CVE-2019-17572 Vulnerability in maven package org.apache.rocketmq:rocketmq-broker
CVE-2020-19698 Vulnerability in maven package org.webjars.bower:editor.md