GMS-2020-791: Command Injection in tree-kill
(updated )
Versions of tree-kill
prior to 1.2.2 are vulnerable to Command Injection. The package fails to sanitize values passed to the kill
function. If this value is user-controlled it may allow attackers to run arbitrary commands in the server. The issue only affects Windows systems.
Recommendation
Upgrade to version 1.2.2 or later.
References
Detect and mitigate GMS-2020-791 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →