Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2020-6537 Vulnerability in npm package electron
CVE-2017-11342 Vulnerability in maven package org.webjars.npm:node-sass
CVE-2015-0254 Vulnerability in maven package org.apache.taglibs:taglibs-standard-impl
CVE-2016-1000229 Vulnerability in npm package swagger-ui
CVE-2021-43138 Vulnerability in maven package org.webjars.bower:async