systeminformation is vulnerable to Command Injection
78
High Risk
Affected versions of this package contain a command injection vulnerability in networkInterfaces() on Linux when parsing NetworkManager connection profile names. The library retrieves connection names from nmcli output and interpolates them into shell commands executed with execSync() without proper sanitization, allowing shell metacharacters in connection names to trigger arbitrary command execution with the privileges of the calling Node.js process.
You are affected if you are using a version that falls within the vulnerable range.
systeminformation is vulnerable to Command Injection in versions 4.17.0 - 5.31.5.
Upgrade the systeminformation library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant