Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2020-28461 Vulnerability in npm package js-ini
CVE-2017-16155 Vulnerability in npm package fast-http-cli
CVE-2022-35916 Vulnerability in npm package @openzeppelin/contracts
CVE-2022-25349 Vulnerability in npm package materialize-css
CVE-2022-40955 Vulnerability in maven package org.apache.inlong:sort-connector-jdbc