Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-26318

Опубликовано: 19 фев. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized locate output in versions(). Version 5.31.0 fixes the issue.

A flaw was found in systeminformation, a System and OS information library for node.js. This vulnerability allows a local attacker with low privileges to inject and execute arbitrary commands due to unsanitized output from the locate command within the versions() function. Successful exploitation can lead to high impact on confidentiality, integrity, and availability of the affected system.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Developer Hubrhdh/rhdh-hub-rhel9Affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2441124systeminformation: systeminformation: Arbitrary code execution via unsanitized `locate` output

EPSS

Процентиль: 7%
0.00027
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
nvd
около 1 месяца назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
github
около 1 месяца назад

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

EPSS

Процентиль: 7%
0.00027
Низкий

8.8 High

CVSS3