CVE-2026-50289
sebhildebrandt systeminformation 취약점
systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu interfaces(5) source directive because lib/network.js checkLinuxDCHPInterfaces() reads /etc/network/interfaces, extracts a source <path> token from file content, and interpolates it unquoted into cat ${file} 2> /dev/null | grep 'iface\|source' executed by execSync(cmd, util.execOptsLinux), allowing a path containing shell metacharacters to execute commands in any process that calls networkInterfaces(), including v...
- 대응 우선순위
- 점검
- CVSS
- 8.7
- EPSS
- 1.87% 백분위 77.3% · 2026.07.31 기준
- CISA KEV
- 미등록
- 조치 기한
- -
- 공개일
- 2026.07.18