← Vulnerability feed

Vulnerability record · CVE-2020-26245 · published 27 November 2020

CVE-2020-26245: Systeminformation os command injection vulnerability

Systeminformation · Systeminformation

npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite().

9.8 CVSS 3.1 Critical EPSS 2.2% · top 17.9% CWE-78 · OS command injectionCWE-471 · CWE-471
9.8CVSS 3.1 base score, v2 7.5
2.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

npm package systeminformation before version 4.30.5 is vulnerable to Prototype Pollution leading to Command Injection. The issue was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. The issue is fixed in version 4.30.5. If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite().

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-26245 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-21315systeminformation npm package command injection via service parametersThe Node.js package systeminformation before 5.3.1 passes service parameters to functions such as si.inetLatency(), si.inetChecksite(), si.services()…KEVEPSS 91%analysed9.8CVE-2023-42810Systeminformation command injection vulnerabilitysysteminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem…EPSS 2.2%9.8CVE-2020-26300Systeminformation command injection vulnerabilitysysteminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is …EPSS 1.4%9.8CVE-2021-21388Systeminformation improper input validation vulnerabilitysysteminformation is an open source system and OS information library for node.js. A command injection vulnerability has been discovered in versions …EPSS 1.9%8.8CVE-2026-26318Systeminformation os command injection vulnerabilitysysteminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `l…EPSS 1.3%8.8CVE-2020-26274Systeminformation os command injection vulnerabilityIn systeminformation (npm package) before version 4.31.1 there is a command injection vulnerability. The problem was fixed in version 4.31.1 with a s…EPSS 2.7%8.8CVE-2020-7752Systeminformation os command injection vulnerabilityThis affects the package systeminformation before 4.27.11. This package is vulnerable to Command Injection. The attacker can concatenate curl's param…EPSS 6.7%8.7CVE-2026-50289Systeminformation os command injection vulnerabilitysysteminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injec…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2020-26245), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.