CVE-2026-26318: Systeminformation

High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

Affected products

Published 2026-02-19. Last modified 2026-07-15.