CVE-2026-26280

EUVD-2026-7969
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the `wifiNetworks()` function sanitizes the `iface` parameter on the initial call (line 437). However, when the initial scan returns empty results, a `setTimeout` retry (lines 440-441) calls `getWifiNetworkListIw(iface)` with the **original unsanitized** `iface` value, which is passed directly to `execSync('iwlist ${iface} scan')`. Any application passing user-controlled input to `si.wifiNetworks()` is vulnerable to arbitrary command execution with the privileges of the Node.js process. Version 5.30.8 fixes the issue.
OS Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
8.4 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 66.66%
Affected Products (NVD)
VendorProductVersion
systeminformationsysteminformation
𝑥
< 5.30.8
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
jupyterlab
forky
4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-3
fixed
sid
4.4.10+ds1+~3.1.0+~0.16.6+~cs1.4.4-4
fixed
trixie
vulnerable
node-systeminformation
forky
5.31.7-1
fixed
sid
5.31.7-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
jupyterlab
jammy
dne
noble
dne
questing
ignored
resolute
needs-triage
node-systeminformation
jammy
dne
noble
dne
questing
dne
resolute
dne