Junglewise Threat Intelligence

CVE-2026-26318: sebhildebrandt systeminformation command injection in versions function

CVE-2026-26318 · Severity: high · CVSS 8.8 · Published 2026-02-19

Technologies: Sebhildebrandt Systeminformation, Red Hat Developer Hub. Vendors: Red Hat, npm.

Executive brief

systeminformation is a widely-used npm package (5M+ weekly downloads) that monitors and reports system information for health dashboards and monitoring tools. The library contains a command injection flaw in its PostgreSQL version detection on Linux: it runs the locate command to find PostgreSQL binaries, then directly concatenates the result into another shell command without proper sanitization. An attacker with local file creation privileges can craft filenames containing shell commands that get indexed by the system's locate database. When any application using systeminformation queries for PostgreSQL version information, the injected commands execute with the privileges of that application—potentially compromising monitoring agents, CI/CD pipelines, or containerized services.

Technical details

The vulnerability exists in lib/osinfo.js within the versions() function. On Linux systems, the code executes `locate bin/postgres`, splits and sorts the output alphabetically, then concatenates the last result into a second exec() call: `exec(postgresqlBin[postgresqlBin.length - 1] + ' -V', ...)`. Because Linux filenames can contain semicolons and exec() passes strings through /bin/sh -c, a malicious filename like `/var/tmp/x;touch /tmp/pwned;/bin/postgres` will cause the shell to interpret the embedded command as a separate statement. The locate command reads from the system-wide plocate.db or mlocate.db database, which is automatically updated daily (via systemd timers or cron) and indexes all readable files on the filesystem. An attacker needs local file creation rights, the locate command to be installed, and a PostgreSQL binary already indexed for this to be exploitable. The code path is Linux-only and has no sanitization (sanitizeShellString() is not used). The fix in version 5.31.0 uses execFile() instead of exec() or adds proper path validation, preventing shell interpretation of filenames.

Affected products

  • sebhildebrandt systeminformation <= 5.30.7

Timeline

  • 2026-02-18: disclosed: GHSA-5vv4-hvf7-2h46 published
  • 2026-02-15: patched: Fix committed (version 5.31.0)

References

Related threats