Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26318

Опубликовано: 19 фев. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized locate output in versions(). Version 5.31.0 fixes the issue.

A flaw was found in systeminformation, a System and OS information library for node.js. This vulnerability allows a local attacker with low privileges to inject and execute arbitrary commands due to unsanitized output from the locate command within the versions() function. Successful exploitation can lead to high impact on confidentiality, integrity, and availability of the affected system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Will not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2441124systeminformation: systeminformation: Arbitrary code execution via unsanitized `locate` output

EPSS

Процентиль: 64%
0.0115
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
nvd
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
debian
6 месяцев назад

systeminformation is a System and OS information library for node.js. ...

CVSS3: 8.8
github
6 месяцев назад

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

EPSS

Процентиль: 64%
0.0115
Низкий

8.8 High

CVSS3