Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-26318

Опубликовано: 19 фев. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.8

Описание

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized locate output in versions(). Version 5.31.0 fixes the issue.

РелизСтатусПримечание
devel

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

DNE

questing

ignored

end of life, was needs-triage
resolute

needs-triage

upstream

released

4.0.11+ds5+~cs11.25.27-1

Показывать по

РелизСтатусПримечание
devel

needs-triage

jammy

DNE

noble

DNE

questing

DNE

resolute

DNE

upstream

not-affected

debian: Fixed before initial upload to Debian

Показывать по

Ссылки на источники

EPSS

Процентиль: 64%
0.0115
Низкий

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
redhat
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
nvd
6 месяцев назад

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CVSS3: 8.8
debian
6 месяцев назад

systeminformation is a System and OS information library for node.js. ...

CVSS3: 8.8
github
6 месяцев назад

Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation

EPSS

Процентиль: 64%
0.0115
Низкий

8.8 High

CVSS3