Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2025-68154

Опубликовано: 16 дек. 2025
Источник: ubuntu
Приоритет: medium
EPSS Средний
CVSS3: 8.1

Описание

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the fsSize() function in systeminformation is vulnerable to OS command injection on Windows systems. The optional drive parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to fsSize(), it is not vulnerable. Version 5.27.14 contains a patch.

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

released

4.0.11+ds5+~cs11.25.27-1

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

debian: Fixed before initial upload to Debian

Показывать по

Ссылки на источники

EPSS

Процентиль: 96%
0.13175
Средний

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
redhat
8 месяцев назад

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch.

CVSS3: 8.1
nvd
8 месяцев назад

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch.

CVSS3: 8.1
debian
8 месяцев назад

systeminformation is a System and OS information library for node.js. ...

CVSS3: 8.1
github
8 месяцев назад

systeminformation has a Command Injection vulnerability in fsSize() function on Windows

EPSS

Процентиль: 96%
0.13175
Средний

8.1 High

CVSS3