Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/703415
Related Vulnerabilities
CVE-2020-28441 Vulnerability in npm package conf-cfg-ini
CVE-2021-32640 Vulnerability in npm package ws
CVE-2019-15954 Vulnerability in npm package total.js
CVE-2019-15657 Vulnerability in maven package org.webjars.npm:eslint-utils
CVE-2021-28163 Vulnerability in maven package org.eclipse.jetty:jetty-deploy