Node.js Systeminformation Command Injection

By
Anandhu K A
Published on
01 Oct 2021
Vulnerability

The Node.JS System Information Library (npm package “systeminformation”) is an open-source set of functions for retrieving detailed hardware, system, and operating system information. There is a command injection vulnerability in system information prior to version 5.3.1. The issue was resolved in version 5.3.1.

Mitigation / Precaution

We suggest you update to the latest version


Written by
Anandhu K A
Anandhu K A
Lead Engineer
Experience the Beagle Security platform
Unlock one full penetration test and all Advanced plan features free for 10 days