VDB
Sign up
HIGH8.1

GHSA-4v2w-h9jm-mqjg

Prototype Pollution in systeminformation

Quick fix

GHSA-4v2w-h9jm-mqjg — systeminformation: upgrade to the fixed version with the command below.

npm install systeminformation@4.30.5

Details

### Impact command injection vulnerability by prototype pollution

### Patches Problem was fixed with a rewrite of shell sanitations to avoid prototyper pollution problems. Please upgrade to version >= 4.30.2

### Workarounds If you cannot upgrade, be sure to check or sanitize service parameter strings that are passed to si.inetChecksite()

### For more information If you have any questions or comments about this advisory:

* Open an issue in [systeminformation](https://github.com/sebhildebrandt/systeminformation/issues/new?template=bug_report.md)

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/systeminformation
Introduced in: 0Fixed in: 4.30.5
Fixnpm install systeminformation@4.30.5

References