systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized locate output in versions(). Version 5.31.0 fixes the issue.
locate
versions()
{ "binaries": [ { "binary_version": "4.0.11+ds1+~cs11.25.27-7", "binary_name": "jupyterlab" } ] }
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-26318.json"
{ "binaries": [ { "binary_version": "4.0.11+ds1+~cs11.25.27-9", "binary_name": "jupyterlab" } ] }