Vulnerabilities/

systeminformation has a Command Injection vulnerability in fsSize() function on Windows

Severity:
High

Description

The fsSize() function in systeminformation is vulnerable to OS Command Injection (CWE-78) on Windows systems. The optional drive parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function.

Recommendation

Update the systeminformation package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
systeminformation
Anything's wrong? Let us know Last updated on December 16, 2025