CVE-2026-26280Disclosure(systeminformation / systeminformation)

LOWCVSS 7.8 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch systeminformation systeminformation systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the `wifiNetworks()` function sanitizes the `iface` parameter on the initial call (line 437). However, when the initial scan returns empty results, a `setTimeout` retry (lines 440-441) calls `getWifiNetworkListIw(iface)` with the **original unsanitized** `iface` value, which is passed directly to `execSync('iwlist ${iface} scan')`. Any application passing user-controlled input to `si.wifiNetworks()` is vulnerable to arbitrary command execution with the privileges of the Node.js process. Version 5.30.8 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • systeminformation

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • Peaked at 2 mentions on most recent observed day (2026-02-20)
  • 3 total mentions across 2 days

Affected systems

Products
systeminformation

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-19: 1Mentions · 2026-02-20: 2Patch / Workaround · 2026-02-20: 1Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 202-1902-20
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-02-202
Disclosure1Patch1
Full discourse3 posts
  • PulsePatch.io@pulsepatchio
    Patch

    `systeminformation` (CVE-2026-26280) is vulnerable to command injection via unsanitized `interface` parameter in `wifi.js`. Update to mitigate #commandinjection #infosec #nodejs https://www.pulsepatch.io/posts/cve-2026-26280-systeminformation-command-injection

    Post summary

    The post discloses a command‑injection flaw (CVE‑2026‑26280) in systeminformation and recommends applying an update to mitigate it; no PoC, exploit tool, or active exploitation evidence is provided.

    0000034
    1 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26280 systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function … https://www.cve.org/CVERecord?id=CVE-2026-26280

    Post summary

    The post notes a command injection flaw in systeminformation's wifiNetworks() function affecting versions before 5.30.8, without providing PoC, exploit code, or patch details.

    00000535
    56.4K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-26280** pertains to a command injection vulnerability in the `systeminformation` library for Node.js, specifically affecting versions prior to 5.30.8. The vulnerability exists within the `wifiNetworks()` function, which is used to retrieve Wi-Fi network information on the host system. #Cybersecurity #CVE #HighSeverity #SecurityAlert https://cvetodo.com/cve/CVE-2026-26280

    Post summary

    The post announces CVE-2026-26280, a command injection vulnerability in Node.js's systeminformation library affecting wifiNetworks() on older versions. It provides technical details but does not discuss exploits, patches, or active attacks.

    0000049
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsysteminformationsysteminformation-node.js-

Explore more