CVE-2026-26318: Systeminformation
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
Affected products
- Systeminformation Systeminformation: before 5.31.0 (fixed in 5.31.0)
Published 2026-02-19. Last modified 2026-07-15.