{"id":"CVE-2019-15599","aliases":[],"url":"https://o3.security/vulnerability/CVE-2019-15599","summary":"Command Injection in tree-kill","details":"Versions of `tree-kill` prior to 1.2.2 are vulnerable to Command Injection. The package fails to sanitize values passed to the  `kill` function. If this value is user-controlled it  may allow attackers to run arbitrary commands in the server. The issue only affects Windows systems.\n\n\n## Recommendation\n\nUpgrade to version 1.2.2 or later.","published":"2020-09-04T16:57:20Z","modified":"2023-11-08T20:41:33.741103Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"npm","name":"tree-kill","fixedVersion":"1.2.2"}],"fix":{"url":"https://github.com/pkrumins/node-tree-kill/commit/deee138a8cbc918463d8af5ce8c2bec33c3fd164","label":"pkrumins/node-tree-kill@deee138"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15599"},{"type":"WEB","url":"https://github.com/pkrumins/node-tree-kill/commit/deee138a8cbc918463d8af5ce8c2bec33c3fd164"},{"type":"WEB","url":"https://hackerone.com/reports/701183"},{"type":"PACKAGE","url":"https://github.com/pkrumins/node-tree-kill"},{"type":"WEB","url":"https://github.com/pkrumins/node-tree-kill/releases/tag/v1.2.2"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2023-11-08T20:41:33.741103Z"}}