Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-44724

Опубликовано: 27 мая 2026
Источник: redhat
CVSS3: 7.8
EPSS Низкий

Описание

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name before using it in shell commands, but it does not apply equivalent sanitization to the parsed NetworkManager connection profile name. That unsanitized connectionName is then interpolated into three shell command strings executed through execSync(). This vulnerability is fixed in 5.31.6.

A flaw was found in systeminformation, a Node.js library. This vulnerability allows a local attacker on Linux to inject arbitrary commands. This occurs when an active NetworkManager connection profile name contains shell metacharacters, which are not properly sanitized before being used in shell commands. Successful exploitation can lead to arbitrary code execution.

Отчет

This Important flaw in the systeminformation Node.js library allows a local attacker to achieve arbitrary command execution on Linux systems. The vulnerability arises when an active NetworkManager connection profile name contains shell metacharacters, which are not properly sanitized before being processed by the library. Exploitation requires the attacker to have privileges to create or rename NetworkManager connection profiles.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat-openshift-console-plugin-npmNot affected
Multicluster Engine for Kubernetesmulticluster-engine/console-mce-rhel9Not affected
Red Hat Advanced Cluster Management for Kubernetes 2rhacm2/console-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-automl-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-autorag-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-eval-hub-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-maas-rhel9Affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-mod-arch-mlflow-rhel9Affected
Red Hat Developer Hub 1.9rhdh/rhdh-hub-rhel9FixedRHSA-2026:3357430.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-78
https://bugzilla.redhat.com/show_bug.cgi?id=2482416systeminformation: systeminformation: Command injection via NetworkManager connection profile name

EPSS

Процентиль: 46%
0.0062
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
ubuntu
2 месяца назад

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name before using it in shell commands, but it does not apply equivalent sanitization to the parsed NetworkManager connection profile name. That unsanitized connectionName is then interpolated into three shell command strings executed through execSync(). This vulnerability is fixed in 5.31.6.

CVSS3: 7.8
nvd
2 месяца назад

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name before using it in shell commands, but it does not apply equivalent sanitization to the parsed NetworkManager connection profile name. That unsanitized connectionName is then interpolated into three shell command strings executed through execSync(). This vulnerability is fixed in 5.31.6.

CVSS3: 7.8
debian
2 месяца назад

systeminformation is a System and OS information library for node.js. ...

CVSS3: 7.8
github
3 месяца назад

Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection profile name

EPSS

Процентиль: 46%
0.0062
Низкий

7.8 High

CVSS3