GHSA-2m8v-572m-ff2v · Severity: high · Ecosystem: npm — Command Injection Vulnerability
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
Conclusion & alert: CVE-2021-21315 is rated Critical Active Threat (84.5/100): CVSS High severity, with high exploitation likelihood (EPSS 90.24%, 100th percentile). Core evidence: CISA KEV confirms active exploitation (added 2022-01-18) affecting Npm package / System Information Library for Node.JS. a weakness (CWE-78) Unauthenticated remote administrative access may be possible. Mandatory action: The CISA remediation deadline has passed—treat as an emergency patch priority.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
: System Information Library for Node.JS Command Injection · CISA KEV detail
: 2022-01-18
: 2022-02-01
: Apply updates per vendor instructions.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 94.02% | 90.24% | -3.78% |
| 2 | 2026-04-27 | 93.94% | 94.02% | +0.08% |
| 3 | 2026-04-15 | — | 93.94% | — |
Full EPSS history (38 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.1 | 3.1 | HIGH |
|
2.5 | 4.0 | [email protected] |
| 7.8 | 3.1 | HIGH |
|
1.8 | 5.9 | [email protected] |
| 4.6 | 2.0 | MEDIUM |
|
3.9 | 6.4 | [email protected] |
GHSA-2m8v-572m-ff2v · Severity: high · Ecosystem: npm — Command Injection Vulnerability
| vendor | priority | summary | link |
|---|---|---|---|
debian
|
unimportant | CVE-2021-21315 unimportant priority: Debian including 1 source packages (node-systeminformation), 2 status rows across 2 suites (forky, sid): resolved 2. | https://security-tracker.debian.org/tracker/CVE-2021-21315 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| systeminformation | systeminformation | < 5.3.1 | cpe:2.3:a:systeminformation:systeminformation:*:*:*:*:*:node.js:*:* |
| apache | cordova | 10.0.0 | cpe:2.3:a:apache:cordova:10.0.0:*:*:*:*:-:*:* |