A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
- https://hackerone.com/reports/701183
- https://github.com/leoambrus/artefactswithoutCVEonGitHubAdvisoryDatabase