systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch.

zetlyn/cve-nvd vulnerability cve CVE-2025-68154 cpe cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:* cpe cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* known 2025-12-16

https://nvd.nist.gov/vuln/detail/CVE-2025-68154

Properties

cvss8.1
receipt
Source
NVD
Its words
8.1
Read by
field:cve.metrics.cvssMetricV31[].cvssData.baseScore
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "systeminformation",
            "vendor": "sebhildebrandt",
            "versions": [
              {
                "status": "affected",
                "version": "< 5.27.14"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4E586FA2-BB8A-49BC-AB57-A8D3F539FCC2",
                "versionEndExcluding": "5.27.14",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch."
      },
      {
        "lang": "es",
        "value": "systeminformation es una biblioteca de información del sistema y del SO para node.js. En versiones anteriores a la 5.27.14, la función 'fsSize()' en systeminformation es vulnerable a la inyección de comandos del SO en sistemas Windows. El parámetro opcional 'drive' se concatena directamente en un comando de PowerShell sin sanitización, lo que permite la ejecución arbitraria de comandos cuando la entrada controlada por el usuario llega a esta función. La explotabilidad real depende de cómo las aplicaciones utilizan esta función. Si una aplicación no pasa entrada controlada por el usuario a 'fsSize()', no es vulnerable. La versión 5.27.14 contiene un parche."
      }
    ],
    "id": "CVE-2025-68154",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-68154",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-17T14:50:36.446709Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-16T19:16:00.257",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/commit/c52f9fd07fef42d2d8e8c66f75b42178da701c68"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-wphj-fx3q-84ch"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
productsysteminformation
receipt
Source
NVD
Its words
systeminformation
Read by
field:cve.affected[].affectedData[].product
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "systeminformation",
            "vendor": "sebhildebrandt",
            "versions": [
              {
                "status": "affected",
                "version": "< 5.27.14"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4E586FA2-BB8A-49BC-AB57-A8D3F539FCC2",
                "versionEndExcluding": "5.27.14",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch."
      },
      {
        "lang": "es",
        "value": "systeminformation es una biblioteca de información del sistema y del SO para node.js. En versiones anteriores a la 5.27.14, la función 'fsSize()' en systeminformation es vulnerable a la inyección de comandos del SO en sistemas Windows. El parámetro opcional 'drive' se concatena directamente en un comando de PowerShell sin sanitización, lo que permite la ejecución arbitraria de comandos cuando la entrada controlada por el usuario llega a esta función. La explotabilidad real depende de cómo las aplicaciones utilizan esta función. Si una aplicación no pasa entrada controlada por el usuario a 'fsSize()', no es vulnerable. La versión 5.27.14 contiene un parche."
      }
    ],
    "id": "CVE-2025-68154",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-68154",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-17T14:50:36.446709Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-16T19:16:00.257",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/commit/c52f9fd07fef42d2d8e8c66f75b42178da701c68"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-wphj-fx3q-84ch"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
statusAnalyzed
receipt
Source
NVD
Its words
Analyzed
Read by
field:cve.vulnStatus
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "systeminformation",
            "vendor": "sebhildebrandt",
            "versions": [
              {
                "status": "affected",
                "version": "< 5.27.14"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4E586FA2-BB8A-49BC-AB57-A8D3F539FCC2",
                "versionEndExcluding": "5.27.14",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch."
      },
      {
        "lang": "es",
        "value": "systeminformation es una biblioteca de información del sistema y del SO para node.js. En versiones anteriores a la 5.27.14, la función 'fsSize()' en systeminformation es vulnerable a la inyección de comandos del SO en sistemas Windows. El parámetro opcional 'drive' se concatena directamente en un comando de PowerShell sin sanitización, lo que permite la ejecución arbitraria de comandos cuando la entrada controlada por el usuario llega a esta función. La explotabilidad real depende de cómo las aplicaciones utilizan esta función. Si una aplicación no pasa entrada controlada por el usuario a 'fsSize()', no es vulnerable. La versión 5.27.14 contiene un parche."
      }
    ],
    "id": "CVE-2025-68154",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-68154",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-17T14:50:36.446709Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-16T19:16:00.257",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/commit/c52f9fd07fef42d2d8e8c66f75b42178da701c68"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-wphj-fx3q-84ch"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}
vendorsebhildebrandt
receipt
Source
NVD
Its words
sebhildebrandt
Read by
field:cve.affected[].affectedData[].vendor
Said since
2026-10-02 12:00 UTC
Last answered
2026-10-04 18:16 UTC
Original
open at the source
What the source handed over
{
  "cve": {
    "affected": [
      {
        "affectedData": [
          {
            "product": "systeminformation",
            "vendor": "sebhildebrandt",
            "versions": [
              {
                "status": "affected",
                "version": "< 5.27.14"
              }
            ]
          }
        ],
        "source": "security-advisories@github.com"
      }
    ],
    "configurations": [
      {
        "nodes": [
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:*",
                "matchCriteriaId": "4E586FA2-BB8A-49BC-AB57-A8D3F539FCC2",
                "versionEndExcluding": "5.27.14",
                "vulnerable": true
              }
            ],
            "negate": false,
            "operator": "OR"
          },
          {
            "cpeMatch": [
              {
                "criteria": "cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*",
                "matchCriteriaId": "A2572D17-1DE6-457B-99CC-64AFD54487EA",
                "vulnerable": false
              }
            ],
            "negate": false,
            "operator": "OR"
          }
        ],
        "operator": "AND"
      }
    ],
    "cveTags": [],
    "descriptions": [
      {
        "lang": "en",
        "value": "systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch."
      },
      {
        "lang": "es",
        "value": "systeminformation es una biblioteca de información del sistema y del SO para node.js. En versiones anteriores a la 5.27.14, la función 'fsSize()' en systeminformation es vulnerable a la inyección de comandos del SO en sistemas Windows. El parámetro opcional 'drive' se concatena directamente en un comando de PowerShell sin sanitización, lo que permite la ejecución arbitraria de comandos cuando la entrada controlada por el usuario llega a esta función. La explotabilidad real depende de cómo las aplicaciones utilizan esta función. Si una aplicación no pasa entrada controlada por el usuario a 'fsSize()', no es vulnerable. La versión 5.27.14 contiene un parche."
      }
    ],
    "id": "CVE-2025-68154",
    "lastModified": "2026-09-30T23:10:00.237",
    "metrics": {
      "cvssMetricV31": [
        {
          "cvssData": {
            "attackComplexity": "HIGH",
            "attackVector": "NETWORK",
            "availabilityImpact": "HIGH",
            "baseScore": 8.1,
            "baseSeverity": "HIGH",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "privilegesRequired": "NONE",
            "scope": "UNCHANGED",
            "userInteraction": "NONE",
            "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H",
            "version": "3.1"
          },
          "exploitabilityScore": 2.2,
          "impactScore": 5.9,
          "source": "security-advisories@github.com",
          "type": "Secondary"
        }
      ],
      "ssvcV203": [
        {
          "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
          "ssvcData": {
            "id": "CVE-2025-68154",
            "options": [
              {
                "exploitation": "none"
              },
              {
                "automatable": "no"
              },
              {
                "technicalImpact": "total"
              }
            ],
            "role": "CISA Coordinator",
            "timestamp": "2025-12-17T14:50:36.446709Z",
            "version": "2.0.3"
          }
        }
      ]
    },
    "published": "2025-12-16T19:16:00.257",
    "references": [
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Patch"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/commit/c52f9fd07fef42d2d8e8c66f75b42178da701c68"
      },
      {
        "source": "security-advisories@github.com",
        "tags": [
          "Exploit",
          "Mitigation",
          "Vendor Advisory"
        ],
        "url": "https://github.com/sebhildebrandt/systeminformation/security/advisories/GHSA-wphj-fx3q-84ch"
      }
    ],
    "sourceIdentifier": "security-advisories@github.com",
    "vulnStatus": "Analyzed",
    "weaknesses": [
      {
        "description": [
          {
            "lang": "en",
            "value": "CWE-78"
          }
        ],
        "source": "security-advisories@github.com",
        "type": "Secondary"
      }
    ]
  }
}

Text

systeminformation is a System and OS information library for node.js. In versions prior to 5.27.14, the `fsSize()` function in systeminformation is vulnerable to OS command injection on Windows systems. The optional `drive` parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function. The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to `fsSize()`, it is not vulnerable. Version 5.27.14 contains a patch. systeminformation es una biblioteca de información del sistema y del SO para node.js. En versiones anteriores a la 5.27.14, la función 'fsSize()' en systeminformation es vulnerable a la inyección de comandos del SO en sistemas Windows. El parámetro opcional 'drive' se concatena directamente en un comando de PowerShell sin sanitización, lo que permite la ejecución arbitraria de comandos cuando la entrada controlada por el usuario llega a esta función. La explotabilidad real depende de cómo las aplicaciones utilizan esta función. Si una aplicación no pasa entrada controlada por el usuario a 'fsSize()', no es vulnerable. La versión 5.27.14 contiene un parche.