Node.js.System.Information.Library.Command.Injection
Description
This indicates an attack attempt to exploit a Command Injection vulnerability in Node.js.
The vulnerability is due to insufficient sanitizing of user supplied inputs in the application. A remote attacker may be able to exploit this to execute arbitrary commands via a crafted request.
Affected Products
Node.js System Information Library prior to 5.3.1
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the most recent upgrade or patch from the vendor.
https://www.npmjs.com/package/systeminformation
Version Updates
| Date | Version | Status | Detail |
|---|---|---|---|
| 2026-01-31 | 1.00069 |
New
|