1.2.2
12 years ago
5 years ago
Known vulnerabilities in the tree-kill package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for freeVulnerability | Vulnerable Version |
---|---|
tree-kill is a package to kill all processes in the process tree, including the root process. Affected versions of this package are vulnerable to Command Injection. User input is concatenated with a Note: This vulnerability is only applicable if the package is used on a Windows operating system. PoC by mik317
How to fix Command Injection? Upgrade | <1.2.2 |