Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2023-45818 Vulnerability in maven package org.webjars.npm:tinymce
CVE-2018-1000529 Vulnerability in maven package org.grails.plugins:fields
CVE-2022-0086 Vulnerability in npm package uppy
CVE-2021-39134 Vulnerability in npm package @npmcli/arborist
CVE-2018-8008 Vulnerability in maven package org.apache.storm:storm-server