Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2021-41165 Vulnerability in npm package ckeditor4
CVE-2022-2216 Vulnerability in npm package parse-url
CVE-2020-28442 Vulnerability in maven package org.webjars.bower:js-data
CVE-2020-6461 Vulnerability in maven package org.webjars.npm:electron
CVE-2017-3589 Vulnerability in maven package mysql:mysql-connector-java