CVE-2025-68154: Systeminformation
High severity, CVSS 8.1. EPSS: 13% chance of exploitation in the next 30 days.
systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch.
Affected products
- Systeminformation Systeminformation: before 5.27.14 (fixed in 5.27.14)
Published 2025-12-16. Last modified 2026-09-30.