HIGH🇵🇱 Wersja polska

CVE-2020-26245

CVSS 8.1v3.1pub. 2020-11-27upd. 2024-11-21

npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite().

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:L/A:L
  • Systeminformation

    APP
    Systeminformation
    < 4.30.5
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Command Injection
CWE
References

Related vulnerabilities

CVE-2023-42810CRITICAL9.8PL ✓same product

Command Injection w bibliotece systeminformation dla Node.JS (SSID)

CVE-2021-21315HIGH7.1⚠ KEVsame product

The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of f...

CVE-2026-50289HIGH8.7PL ✓same product

Command injection w bibliotece systeminformation — funkcja networkInterfaces()

CVE-2026-26280HIGH8.4same product

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command i...

CVE-2026-26318HIGH8.8same product

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable ...