Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
Remediation
References
https://hackerone.com/reports/701183
Related Vulnerabilities
CVE-2017-16183 Vulnerability in npm package iter-server
CVE-2021-30109 Vulnerability in npm package froala-editor
CVE-2018-16491 Vulnerability in maven package org.webjars.npm:node.extend
CVE-2021-25978 Vulnerability in npm package apostrophe
CVE-2018-1000409 Vulnerability in maven package org.jenkins-ci.main:jenkins-core