CVE-2020-26274: Command Injection Vulnerability in systeminformation
In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for the systeminformation npm package?
The vulnerability ID for the systeminformation npm package is CVE-2020-26274.
What is the severity of CVE-2020-26274?
The severity of CVE-2020-26274 is high with a severity value of 8.8.
What is the affected software for CVE-2020-26274?
The affected software for CVE-2020-26274 is systeminformation (npm package) before version 4.31.1.
How can I fix CVE-2020-26274?
You can fix CVE-2020-26274 by updating to version 4.31.1 or later of the systeminformation npm package.
Is there any additional information available about CVE-2020-26274?
Yes, you can find additional information about CVE-2020-26274 in the references: [GitHub Commit](https://github.com/sebhildebrandt/systeminformation/commit/1faadcbf68f1b1fdd5eb2054f68fc932be32ac99), [GitHub Security Advisories](https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-m57p-p67h-mq74), [NPM Package](https://www.npmjs.com/package/systeminformation).