CVE-2026-26280: Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path
Summary A command injection vulnerability in the wifiNetworks() function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path.
Details In lib/wifi.js, the wifiNetworks() function sanitizes the iface parameter on the initial call (line 437). However, when the initial scan returns empty results, a setTimeout retry (lines 440-441) calls getWifiNetworkListIw(iface) with the original unsanitized iface value, which is passed directly to execSync('iwlist ${iface} scan').
PoC 1. Install systeminformation@5.30.7 2. Call si.wifiNetworks('eth0; id') 3. The first call sanitizes input, but if results are empty, the retry executes: iwlist eth0; id scan
Impact Remote Code Execution (RCE). Any application passing user-controlled input to si.wifiNetworks() is vulnerable to arbitrary command execution with the privileges of the Node.js process.
Other sources
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the wifiNetworks() function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In lib/wifi.js, the wifiNetworks() function sanitizes the iface parameter on the initial call (line 437). However, when the initial scan returns empty results, a setTimeout retry (lines 440-441) calls getWifiNetworkListIw(iface) with the original unsanitized iface value, which is passed directly to execSync('iwlist ${iface} scan'). Any application passing user-controlled input to si.wifiNetworks() is vulnerable to arbitrary command execution with the privileges of the Node.js process. Version 5.30.8 fixes the issue.
— NVD
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/systeminformationto a version that resolves this vulnerability.Fixed in 5.30.8 - Upgrade
Upgrade
systeminformationto a version that resolves this vulnerability.Fixed in 5.30.8
Event History
Frequently Asked Questions
What is the severity of CVE-2026-26280?
CVE-2026-26280 has a high severity rating due to its potential to allow arbitrary command execution.
How do I fix CVE-2026-26280?
To fix CVE-2026-26280, update the 'systeminformation' package to version 5.30.8 or later.
What causes CVE-2026-26280?
CVE-2026-26280 is caused by a command injection vulnerability in the 'wifiNetworks()' function within the 'lib/wifi.js' file.
What happens if CVE-2026-26280 is exploited?
If exploited, CVE-2026-26280 could allow attackers to execute arbitrary operating system commands.
Which software versions are affected by CVE-2026-26280?
CVE-2026-26280 affects versions of the 'systeminformation' package prior to 5.30.8.