Command Injection in tree-kill
High severity
GitHub Reviewed
Published
Sep 4, 2020
to the GitHub Advisory Database
•
Updated Nov 29, 2023
Description
Reviewed
Aug 31, 2020
Published to the GitHub Advisory Database
Sep 4, 2020
Last updated
Nov 29, 2023
Versions of
tree-kill
prior to 1.2.2 are vulnerable to Command Injection. The package fails to sanitize values passed to thekill
function. If this value is user-controlled it may allow attackers to run arbitrary commands in the server. The issue only affects Windows systems.Recommendation
Upgrade to version 1.2.2 or later.
References