<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:15:19.563496+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-361079</id>
    <title>EUVD-2026-361079</title>
    <updated>2026-10-03T18:15:19.848748+00:00</updated>
    <content>EUVD-2026-361079</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-361079"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-44724</id>
    <title>fkie_cve-2026-44724</title>
    <updated>2026-10-03T18:15:19.848846+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name before using it in shell commands, but it does not apply equivalent sanitization to the parsed NetworkManager connection profile name. That unsanitized connectionName is then interpolated into three shell command strings executed through execSync(). This vulnerability is fixed in 5.31.6.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-44724"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-hvx9-hwr7-wjj9</id>
    <title>GHSA-hvx9-hwr7-wjj9 — Systeminformation vulnerable to Linux command injection in networkInterfaces() via unsanitized NetworkManager connectio…</title>
    <updated>2026-10-03T18:15:19.848927+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: systeminformation</p>
<p>## Summary</p>
<p>On Linux, `systeminformation` is vulnerable to command injection in `networkInterfaces()` when an **active NetworkManager connection profile name** contains shell metacharacters.</p>
<p>This is not caused by a caller passing attacker-controlled arguments into `networkInterfaces()`. The vulnerable value is obtained internally from real `nmcli device status` output. The library sanitizes the network interface name before using it in shell commands, but it does **not** apply equivalent sanitization to the parsed NetworkManager connection profile name. That unsanitized `connectionName` is then interpolated into three shell command strings executed through `execSync()`.</p>
<p>This issue was validated locally against **real NetworkManager** and **real `nmcli`**. Calling only:</p>
<p>```js
require('./lib').networkInterfaces()
```</p>
<p>was enough to trigger execution. The injected command ran with the privileges of the calling Node.js process.</p>
<p>## Affected Component &amp; Versions</p>
<p>**Affected component:**</p>
<p>- [`lib/network.js`](https://github.com/sebhildebrandt/systeminformation/blob/ed1cac537c59763301d802ad1b55b4b8581e7553/lib/network.js)
- `networkInterfaces()`
- Linux NetworkManager / `nmcli` handling</p>
<p>## Impact &amp; Threat Model</p>
<p>**Confirmed impact:**</p>
<p>An attacker who can create or rename an **active NetworkManager connection profile** can execute arbitrary shell commands when a Node.js process using `systeminformation` calls `networkInterfaces()`.</p>
<p>**Confirmed realistic affected deployments in…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-hvx9-hwr7-wjj9"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2026:33574</id>
    <title>RHSA-2026:33574 — Red Hat Security Advisory: Red Hat Developer Hub 1.9.6 release.</title>
    <updated>2026-10-03T18:15:19.849269+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>shell-quote: shell-quote: Arbitrary code execution via command injection due to unescaped line terminators json-2-csv: json-2-csv: CSV Injection vulnerability allows arbitrary code execution via `preventCsvInjection` bypass. crypto/x509: golang: golang crypto/x509: Denial of Service via excessive processing of DNS SAN entries net: golang: Go net package: Denial of Service via long CNAME response in LookupCNAME net/mail: golang: Go net/mail: Denial of Service via crafted email inputs axios: Axios: HTTP Transport Hijacking via Prototype Pollution axios: Axios: Arbitrary HTTP header injection via prototype pollution axios: Node.js: Axios: Denial of Service via unbounded recursion in toFormData with deeply nested request data axios: Axios: Authentication bypass due to prototype pollution of HTTP error handling axios: Axios: NO_PROXY bypass via crafted URL axios: Axios: Invisible JSON Response Tampering via Prototype Pollution Gadget ip-address: ip-address: Cross-site scripting via improper HTML escaping of untrusted input net/mail: golang: net/mail: Denial of Service via pathological email address parsing axios: Axios: Information disclosure of proxy credentials via HTTP redirects axios: Axios: Information disclosure of proxy credentials via redirect flows axios: Axios: Denial of Service due to unenforced request and response size limits axios: Axios: Proxy bypass via IPv4-mapped IPv6 address non-normalization axios: Axios: Man-in-the-Middle (MITM) attack via Prototype Pollution…</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2026:33574"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44724</id>
    <title>UBUNTU-CVE-2026-44724</title>
    <updated>2026-10-03T18:15:19.849427+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:25.10: jupyterlab, Ubuntu:26.04:LTS: jupyterlab</p>
<p>systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active NetworkManager connection profile name contains shell metacharacters. The vulnerable value is obtained internally from real nmcli device status output. The library sanitizes the network interface name before using it in shell commands, but it does not apply equivalent sanitization to the parsed NetworkManager connection profile name. That unsanitized connectionName is then interpolated into three shell command strings executed through execSync(). This vulnerability is fixed in 5.31.6.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-44724"/>
  </entry>
</feed>
