Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/703415
Related Vulnerabilities
CVE-2018-13863 Vulnerability in maven package org.webjars.npm:bson
CVE-2021-25948 Vulnerability in npm package expand-hash
CVE-2021-41183 Vulnerability in npm package jquery-ui
CVE-2017-1000421 Vulnerability in npm package gifsicle
CVE-2021-21364 Vulnerability in maven package io.swagger:swagger-codegen