8.8
/ 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Description
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
AI Analysis
Command injection vulnerability via unsanitized `locate` output in `versions()`
Basic Information
ID
CVE-2026-26318
Source
GitHub_M
Published
Feb 19, 2026 at 19:48
Affected Product
Vendor
sebhildebrandt
Product
systeminformation
Version
< 5.31.0
Affected Versions
sebhildebrandt systeminformation < 5.31.0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
sebhildebrandt
Product
systeminformation
Version
< 5.31.0