Critical severity9.8NVD Advisory· Published Dec 18, 2019· Updated Jun 17, 2026
CVE-2019-15598
CVE-2019-15598
Description
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tree-killnpm | < 1.2.2 | 1.2.2 |
Affected products
3- cpe:2.3:a:treekill_project:treekill:1.0.0:*:*:*:*:node.js:*:*
- treekill/treekilldescription
Patches
Vulnerability mechanics
References
9- github.com/advisories/GHSA-j7fq-p9q7-5wfvghsaADVISORY
- hackerone.com/reports/703415nvdPermissions RequiredThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-15598ghsaADVISORY
- github.com/node-modules/treekill/blob/master/index.jsghsaWEB
- github.com/pkrumins/node-tree-kill/commit/ff73dbf144c4c2daa67799a50dfff59cd455c63cghsaWEB
- github.com/pkrumins/node-tree-kill/issues/30ghsaWEB
- github.com/pkrumins/node-tree-kill/pull/31ghsaWEB
- hackerone.com/reports/701183ghsaWEB
- security.snyk.io/vuln/SNYK-JS-TREEKILL-536781ghsaWEB
News mentions
0No linked articles in our index yet.