VDB
KO
CRITICAL 9.8

GHSA-gx6r-qc2v-3p3v

systeminformation SSID Command Injection Vulnerability

Details

### Impact SSID Command Injection Vulnerability

### Patches Problem was fixed with a parameter check. Please upgrade to version >= 5.21.7, Version 4 was not affected

### Workarounds If you cannot upgrade, be sure to check or sanitize parameter strings that are passed to wifiConnections(), wifiNetworks() (string only)

### References See also https://systeminformation.io/security.html

Are you affected?

Enter the version of the package you're using.

Affected packages

npm / systeminformation
Introduced in: 5.0.0 Fixed in: 5.21.7
Fix npm install systeminformation@5.21.7

References