Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-26318

Опубликовано: 19 фев. 2026
Источник: debian
EPSS Низкий

Описание

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
node-systeminformationnot-affectedpackage
jupyterlabfixed4.0.11+ds5+~cs11.25.27-1package

Примечания

  • node-systeminformation split from jupyterlab

EPSS

Процентиль: 64%
0.0115
Низкий

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
redhat
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
nvd
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
github
6 месяцев назад

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

EPSS

Процентиль: 64%
0.0115
Низкий