logo

Critical Vulnerability in Popular Node.js Library Exposes Windows Systems to RCE Attacks

ID: fddffd59-f62d-53b8-9233-af6666706fb3

STIX ID: report--fddffd59-f62d-53b8-9233-af6666706fb3

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-18

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical OS command injection vulnerability (CVE-2025-68154) was disclosed in the widely used Node.js package systeminformation: versions up to 5.27.13 allow attacker-controlled input passed to fsSize() to be injected into a PowerShell command on Windows, enabling arbitrary command execution. The advisory reports a CVSS score of 7.5, notes the flaw affects applications that pass user input directly to fsSize() (e.g., web apps, APIs, dashboards), and instructs developers to upgrade immediately to version 5.27.14 which properly validates input.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.