Skip to content

[GHSA-884p-74jh-xrg2] Command Injection in tree-kill#7455

Open
Wenxin-Jiang wants to merge 1 commit intoWenxin-Jiang/advisory-improvement-7455from
Wenxin-Jiang-GHSA-884p-74jh-xrg2
Open

[GHSA-884p-74jh-xrg2] Command Injection in tree-kill#7455
Wenxin-Jiang wants to merge 1 commit intoWenxin-Jiang/advisory-improvement-7455from
Wenxin-Jiang-GHSA-884p-74jh-xrg2

Conversation

@Wenxin-Jiang
Copy link
Copy Markdown

Updates

  • Affected products

Comments
CVE-2019-15599 is exploitable only through the Windows branch exec('taskkill /pid ' + pid + ' /T /F'), which was first added in 0.0.4 when process.platform === 'win32' support was introduced.

Versions 0.0.1–0.0.3 are Unix-only and invoke spawn('ps', [...]) exclusively—argv form, no shell, no attacker-controlled string interpolation—so the vulnerable sink does not exist.

Fix commit deee138a (1.2.2) guards the same exec call with parseInt/Number.isNaN, confirming it as the sole sink.

@github-actions github-actions bot changed the base branch from main to Wenxin-Jiang/advisory-improvement-7455 April 20, 2026 14:52
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant