FixVibe

high

Command Injection in kill-port-process (CVE-2019-15609)

kill-port-process versions before 2.2.0 are affected by a command injection. FixVibe GitHub repo scans flag affected kill-port-process versions in npm manifests and lockfiles.

CVE-2019-15609GHSA-xp4x-j9vh-c3wfCWE-77CWE-78

Impact

The reviewed advisories list kill-port-process versions earlier than 2.2.0 as affected by CVE-2019-15609 / GHSA-xp4x-j9vh-c3wf [S1][S2]. The package is used for process-management tasks around ports, so affected versions should be treated as a high-priority dependency update when they appear in a deployed Node.js service, worker, script, or image. A repository dependency match does not by itself prove that the package is present in the deployed runtime or that untrusted input reaches the helper.

Root Cause

The advisory record describes a command-injection issue in the package before the fixed 2.2.0 release [S1][S2]. The original report is linked as source context for the affected package and version range [S3]. Exploitability depends on how an application installs and calls the package.

Covered by FixVibe

FixVibe's GitHub repo scans flag kill-port-process in npm manifests and lockfiles when the declared or resolved version is in the affected range, showing the file, version, advisory IDs and fixed version.

Remediation

Upgrade kill-port-process to 2.2.0 or newer using the package manager the repository actually builds from [S2]. Regenerate the active lockfile, rebuild runtime images, workers, devcontainers, and CI caches that install dependencies, then verify with npm ls kill-port-process, pnpm why kill-port-process, or yarn why kill-port-process. Review any call sites that pass port values to process-termination helpers and keep strict numeric port validation before the helper call.