{
  "id": "CVE-2021-21315",
  "url": "https://spydr.io/cve/CVE-2021-21315",
  "published": "2021-02-16T17:15:13.050Z",
  "modified": "2026-06-17T03:35:16.700Z",
  "score": 7.8,
  "severity": "high",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
  "score_source": "NVD",
  "epss": 0.90675,
  "epss_percentile": 0.99802,
  "exploited": true,
  "kev": {
    "added": "2022-01-18",
    "due": "2022-02-01",
    "action": "Apply updates per vendor instructions.",
    "ransomware": "Unknown",
    "name": "System Information Library for Node.JS Command Injection",
    "notes": "https://nvd.nist.gov/vuln/detail/CVE-2021-21315"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "sebhildebrandt"
  ],
  "products": [
    "sebhildebrandt systeminformation"
  ],
  "cwes": [
    "CWE-78"
  ],
  "description": "The System Information Library for Node.JS (npm package \"systeminformation\") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.",
  "status": "Analyzed",
  "score_type": "Primary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 7.8,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "https://github.com/sebhildebrandt/systeminformation/commit/07daa05fb06f24f96297abaa30c2ace8bfd8b525",
      "tags": [
        "Patch"
      ]
    },
    {
      "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-2m8v-572m-ff2v",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://lists.apache.org/thread.html/r8afea9a83ed568f2647cccc6d8d06126f9815715ddf9a4d479b26b05%40%3Cissues.cordova.apache.org%3E",
      "tags": [
        "Issue Tracking",
        "Mailing List"
      ]
    },
    {
      "url": "https://security.netapp.com/advisory/ntap-20210312-0007/",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "https://www.npmjs.com/package/systeminformation",
      "tags": [
        "Product"
      ]
    },
    {
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21315",
      "tags": [
        "US Government Resource"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2021-21315",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
