Description
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
Problem types
CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
References
github.com/...mation/security/advisories/GHSA-5vv4-hvf7-2h46
github.com/...ommit/b67d3715eec881038ccbaace2f2711419ac3e107