Critical Vulnerability in Popular Node.js Library Exposes Windows Systems to RCE Attacks
ID: fddffd59-f62d-53b8-9233-af6666706fb3
STIX ID: report--fddffd59-f62d-53b8-9233-af6666706fb3
Feed Name: cybersecurityNews.com
A critical OS command injection vulnerability (CVE-2025-68154) was disclosed in the widely used Node.js package systeminformation: versions up to 5.27.13 allow attacker-controlled input passed to fsSize() to be injected into a PowerShell command on Windows, enabling arbitrary command execution. The advisory reports a CVSS score of 7.5, notes the flaw affects applications that pass user input directly to fsSize() (e.g., web apps, APIs, dashboards), and instructs developers to upgrade immediately to version 5.27.14 which properly validates input.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
