Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2023-26140 Vulnerability in npm package @excalidraw/excalidraw
CVE-2019-16548 Vulnerability in maven package org.jenkins-ci.plugins:google-compute-engine
CVE-2020-13959 Vulnerability in maven package org.apache.velocity.tools:velocity-tools-view
CVE-2019-19771 Vulnerability in npm package siganle
CVE-2023-3163 Vulnerability in maven package com.ruoyi:ruoyi-common