Medium severity5.9NVD Advisory· Published Sep 9, 2021· Updated Jun 17, 2026
CVE-2020-26300
CVE-2020-26300
Description
systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
systeminformationnpm | < 4.26.2 | 4.26.2 |
Affected products
3- cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*Range: <4.26.2
- Range: < 4.26.2
Patches
Vulnerability mechanics
References
5- github.com/advisories/GHSA-fj59-f6c3-3vw4nvdPatchThird Party AdvisoryADVISORY
- github.com/sebhildebrandt/systeminformation/commit/bad372e654cdd549e7d786acbba0035ded54c607nvdPatchThird Party AdvisoryWEB
- github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-fj59-f6c3-3vw4nvdThird Party AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2020-26300ghsaADVISORY
- www.npmjs.com/package/systeminformationnvdProductThird Party AdvisoryWEB
News mentions
0No linked articles in our index yet.