CVE-2026-26318OS Command Injection in Systeminformation

Severity
8.8HIGHNVD
EPSS
0.0%
top 92.49%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 19

Description

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:HExploitability: 2.0 | Impact: 6.0

Affected Packages3 packages

Patches

🔴Vulnerability Details

3
CVEList
systeminformation has Command Injection via Unsanitized `locate` Output in `versions()`2026-02-19
GHSA
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation2026-02-18
OSV
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation2026-02-18

📋Vendor Advisories

1
Red Hat
systeminformation: systeminformation: Arbitrary code execution via unsanitized `locate` output2026-02-19

🕵️Threat Intelligence

1
Wiz
CVE-2026-26318 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-26318 — OS Command Injection | cvebase