CVE-2021-21315
sebhildebrandt systeminformation
Published 16 Feb 2021 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 18 Jan 2022, with a remediation deadline of 1 Feb 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
References
- github.com/sebhildebrandt/systeminformation/commit/07daa05fb06f24f96297abaa30c2ace8bfd8b525 · Patch
- github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v · Third Party Advisory
- lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715ddf9a4d479b26b05%40%3Cissues.cordova.apache.org%3E · Issue Tracking, Mailing List
- security.netapp.com/advisory/ntap-20210312-0007/ · Third Party Advisory
- www.npmjs.com/package/systeminformation · Product
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21315 · US Government Resource