Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2018-1999024 Vulnerability in npm package mathjax
CVE-2017-16225 Vulnerability in npm package aegir
CVE-2022-45598 Vulnerability in npm package @joplin/renderer
CVE-2020-24660 Vulnerability in npm package node-lemonldap-ng-handler
CVE-2020-23622 Vulnerability in maven package org.fourthline.cling:cling-core