Critical severity9.8NVD Advisory· Published Dec 18, 2019· Updated Jun 17, 2026
CVE-2019-15599
CVE-2019-15599
Description
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
tree-killnpm | < 1.2.2 | 1.2.2 |
Affected products
3- cpe:2.3:a:tree-kill_project:tree-kill:1.2.1:*:*:*:*:node.js:*:*
- tree-kill/tree-killdescription
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-884p-74jh-xrg2ghsaADVISORY
- hackerone.com/reports/701183nvdPermissions RequiredThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2019-15599ghsaADVISORY
- github.com/pkrumins/node-tree-kill/commit/deee138a8cbc918463d8af5ce8c2bec33c3fd164ghsaWEB
- github.com/pkrumins/node-tree-kill/releases/tag/v1.2.2ghsaWEB
News mentions
0No linked articles in our index yet.