Command Injection Vulnerability in Systeminformation Library for Node.js by Sebastien Hildebrandt
CVE-2026-44724

7.8HIGH

Key Information:

Vendor
CVE Published:
27 May 2026

What is CVE-2026-44724?

The Systeminformation library for Node.js, specifically versions 4.17.0 to 5.31.5, contains a vulnerability allowing command injection through improperly sanitized NetworkManager connection profile names. When these names contain shell metacharacters, the library fails to adequately sanitize the input before interpolating it into shell command strings executed via execSync(). This oversight can potentially allow attackers to execute arbitrary commands on the affected Linux systems. The issue has been rectified in version 5.31.6.

Affected Version(s)

systeminformation >= 4.17.0, < 5.31.6

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.