First published: Wed Dec 16 2020(Updated: )
In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
Credit: security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
Systeminformation Systeminformation Node.js | <4.31.1 |
https://github.com/sebhildebrandt/systeminformation/commit/1faadcbf68f1b1fdd5eb2054f68fc932be32ac99
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the systeminformation npm package is CVE-2020-26274.
The severity of CVE-2020-26274 is high with a severity value of 8.8.
The affected software for CVE-2020-26274 is systeminformation (npm package) before version 4.31.1.
You can fix CVE-2020-26274 by updating to version 4.31.1 or later of the systeminformation npm package.
Yes, you can find additional information about CVE-2020-26274 in the references: [GitHub Commit](https://github.com/sebhildebrandt/systeminformation/commit/1faadcbf68f1b1fdd5eb2054f68fc932be32ac99), [GitHub Security Advisories](https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-m57p-p67h-mq74), [NPM Package](https://www.npmjs.com/package/systeminformation).