CVE-2026-26318

high Red Hat
CVSS v3 Base Score
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Published: February 19, 2026
Last Modified: February 19, 2026
Vendor: Red Hat

Description

systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.

CWE

CWE-78

Affected Products

Red Hat Developer Hub

References