Loading
Generated remediation guidance and an executive summary. No account required.
systeminformation is an npm package that provides system and OS information library for node.js. In systeminformation before version 4.26.2 there is a command injection vulnerability. Problem was fixed in version 4.26.2 with a shell string sanitation fix.
Use CWE-77, Systeminformation vendor hub and Systeminformation product page to widen CVE-2020-26300 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2021-21315, CVE-2023-42810 and CVE-2021-21388 for nearby disclosures in the same product family.