CVE-2026-26318Disclosure(systeminformation / systeminformation)

LOWCVSS 8.8 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch systeminformation systeminformation systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • systeminformation

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • Peaked at 3 mentions on most recent observed day (2026-02-20)
  • 4 total mentions across 2 days

Affected systems

Products
systeminformation

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-19: 1Mentions · 2026-02-20: 3Patch / Workaround · 2026-02-20: 2Technical Details · 2026-02-19: 1Technical Details · 2026-02-20: 302-1902-20
Signal classification2 categories
Disclosure
250.0%
Patch
250.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-02-203
Disclosure1Patch2
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    A command injection flaw (CVE-2026-26318) in `sebhildebrandt/systeminformation` via unsanitized `locate` output can lead to RCE. Users should update to the patched version. #systeminformation #CommandInjection #infosec https://www.pulsepatch.io/posts/cve-2026-26318-systeminformation-command-injection

    Post summary

    A command injection flaw in sebhildebrandt/systeminformation (CVE-2026-26318) can lead to remote code execution; users are advised to update to the patched version.

    0000030
    1 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-26318: HIGH] Attention Node.js users! Update systeminformation to version 5.31.0 to patch a critical command injection vulnerability related to `locate` output sanitization. Stay secure!#cve,CVE-2026-26318,#cybersecurity https://cvefind.com/CVE-2026-26318

    Post summary

    The post warns Node.js users of CVE-2026-26318, a command‑injection flaw in systeminformation, and urges updating to the patched 5.31.0 release.

    0000044
    578 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-26318 systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in … https://www.cve.org/CVERecord?id=CVE-2026-26318

    Post summary

    CVE‑2026‑26318 reveals a command injection flaw in the node.js Systeminformation library (v<5.31.0) caused by unsanitized `locate` output; the text contains no PoC, exploit, or patch details.

    00000144
    56.4K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-26318** pertains to the `systeminformation` library used in Node.js applications. This library provides system and OS information, but versions prior to 5.31.0 are vulnerable to a command injection attack. The root cause is the unsanitized handling of output from the `locate` command within the `versions()` function, which can be exploited by an attacker to execute arbitrary commands on the host system. #Cybersecurity #CVE #HighSeverity #SecurityAlert https://cvetodo.com/cve/CVE-2026-26318

    Post summary

    CVE-2026-26318 is a command-injection flaw in the systeminformation library before version 5.31.0 stemming from unsanitized `locate` output. The text provides technical details but does not mention PoC, exploit code, active exploitation, or any patch.

    0000046
    20 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appsysteminformationsysteminformation-node.js-

Explore more