Vulnerabilities/

Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connection

Severity:
High

Description

On Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters.

This is not caused by a caller passing attacker-controlled arguments into networkInterfaces().

Recommendation

Update the systeminformation package to the latest compatible version. Followings are version details:

References

Related Issues

Tags:
npm
systeminformation
Anything's wrong? Let us know Last updated on May 13, 2026