Количество 3
Количество 3
CVE-2026-26318
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
CVE-2026-26318
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
GHSA-5vv4-hvf7-2h46
Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-26318 systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
CVE-2026-26318 systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue. | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад | |
GHSA-5vv4-hvf7-2h46 Command Injection via Unsanitized `locate` Output in `versions()` — systeminformation | CVSS3: 8.8 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу