REDHAT-BUG-2441124: Command Injection
Published Feb 19, 2026
·Updated
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized locate output in versions(). Version 5.31.0 fixes the issue.
Affected Software
1 affected component
npm/systeminformation<5.31.0
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
systeminformationto a version that resolves this vulnerability.Fixed in 5.31.0
Event History
Feb 19, 2026
Data Sourced
via Red Hat·09:04 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2441124?
The severity of REDHAT-BUG-2441124 is high with a score of 7.
2
How do I fix REDHAT-BUG-2441124?
To fix REDHAT-BUG-2441124, upgrade the systeminformation library to version 5.31.0 or later.
3
What type of vulnerability is REDHAT-BUG-2441124?
REDHAT-BUG-2441124 is a command injection vulnerability.
4
Which versions of systeminformation are affected by REDHAT-BUG-2441124?
Versions of systeminformation prior to 5.31.0 are affected by REDHAT-BUG-2441124.
5
What can be exploited in REDHAT-BUG-2441124?
The vulnerability can be exploited through unsanitized 'locate' output in the versions() function.