Executive brief
systeminformation is a Node.js library used to retrieve system hardware and software information. The fsSize() function on Windows systems contains a command injection flaw that allows arbitrary OS command execution if an application passes user-controlled input to this function. An attacker could exploit this to execute malicious commands with the privileges of the Node.js process.
Technical details
The fsSize() function on Windows directly concatenates an optional drive parameter into a PowerShell command string without sanitization, enabling OS command injection (CWE-78). The vulnerable code constructs a Get-WmiObject PowerShell query by appending user input via string concatenation. An attacker can use semicolons and other shell metacharacters to break out of the intended command and inject arbitrary PowerShell commands. Exploitation requires the application to pass user-controlled input to fsSize(); if an app only calls fsSize() with static parameters or no parameters, it is not vulnerable. The codebase already uses a util.sanitizeShellString() function in other similar functions, but this was not applied in fsSize(). A patch was released in version 5.27.14 that applies proper input sanitization.
Affected products
- systeminformation systeminformation <=5.27.13
Timeline
- 2025-12-16: disclosed: Advisory GHSA-wphj-fx3q-84ch published
- 2025-12-16: patched: Version 5.27.14 released with fix