Systeminformation is a widely embedded Node.js library for retrieving system and hardware information, deployed across a significant range of applications and monitoring tools despite its narrow product scope. Vulnerabilities affecting the library skew strongly toward critical-severity outcomes and have a moderate tendency toward both confirmed in-the-wild exploitation and public exploit availability, reflecting the elevated risk when OS and command injection flaws occur in a supply-chain dependency. The recurring exposure centers on improper neutralization of special elements in OS and shell commands, improper input validation, and data mutation issues that arise from the library's direct interaction with system-level operations. Defenders should audit downstream products that bundle this library and prioritize remediation for injection vulnerabilities; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Systeminformation over time
Signals from CVEs in this vendor scope (11 CVEs).
11 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-21315HIGH The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In | Feb 16, 2021 | 7.8 | 96 | YES | YES |
CVE-2025-68154HIGH systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injecti | Dec 16, 2025 | 8.1 | 35 | NO | NO |
CVE-2020-26300CRITICAL systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerabili | Sep 9, 2021 | 9.8 | 31 | NO | NO |
CVE-2020-26245CRITICAL npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to av | Nov 27, 2020 | 9.8 | 31 | NO | NO |
CVE-2026-26280HIGH systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an atta | Feb 19, 2026 | 7.8 | 30 | NO | NO |
CVE-2023-42810CRITICAL systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter che | Sep 21, 2023 | 9.8 | 30 | NO | NO |
CVE-2026-26318HIGH systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. | Feb 19, 2026 | 8.8 | 29 | NO | NO |
CVE-2021-21388CRITICAL systeminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions of systeminformation prior to 5 | Apr 29, 2021 | 9.8 | 29 | NO | NO |
CVE-2020-26274HIGH In systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a shell string sanitation fix. | Dec 16, 2020 | 8.8 | 28 | NO | NO |
CVE-2020-7752HIGH This affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's parameters to overwrite Javascript f | Oct 26, 2020 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (11 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Systeminformation.
Media articles that mention a CVE ID that affects a product developed by Systeminformation — matched by CVE ID, not by vendor name.