Description
systeminformation is a System Information Library for Node.JS. Versions 5.0.0 through 5.21.6 have a SSID Command Injection Vulnerability. The problem was fixed with a parameter check in version 5.21.7. As a workaround, check or sanitize parameter strings that are passed to `wifiConnections()`, `wifiNetworks()` (string only).
References (3)
Core 3
Core References
Vendor Advisory x_refsource_confirm
https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-gx6r-qc2v-3p3v
Patch x_refsource_misc
https://github.com/sebhildebrandt/systeminformation/commit/7972565812ccb2a610a22911c54c3446f4171392
Vendor Advisory x_refsource_misc
https://systeminformation.io/security.html
Scores
CVSS v3
9.8
EPSS
0.0206
EPSS Percentile
84.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-77
Status
published
Products (2)
npm/systeminformation
5.0.0 - 5.21.7npm
systeminformation/systeminformation
5.0.0 - 5.21.7
Published
Sep 21, 2023
Tracked Since
Feb 18, 2026