CVE-2021-21315
CWE-78
87.5
RPSRPS range: 0–105; KEV-listed vulnerabilities can receive an exploitation amplifier.
Description
The System Information Library for Node.JS (npm package "systeminformation") is an open source collection of functions to retrieve detailed hardware, system and OS information. In systeminformation before version 5.3.1 there is a command injection vulnerability. Problem was fixed in version 5.3.1. As a workaround instead of upgrading, be sure to check or sanitize service parameters that are passed to si.inetLatency(), si.inetChecksite(), si.services(), si.processLoad() ... do only allow strings, reject any arrays. String sanitation works as expected.
Source: NVD
Signals
- CVSS
- 7.1
- High · v3.1
- EPSS
- 90.67%
- Probability of exploitation in the next 30 days (FIRST)
- CISA KEV
- In CISA KEV since Jan 2022
- Fix commit
- Fix commit known
- Sources: MoreFixes, FreshFixes
- Weakness
- CWE-78
- Published
- 16 Feb 2021
- Last modified 24 Oct 2025
How to read these signals: RPS · EPSS · CISA KEV · Data sources
Get this score from the API
curl -H "Authorization: Bearer dsec_live_xxxxxxxx" \
https://api.intelligence.devsecure.io/api/v1/rps/CVE-2021-21315Replace the placeholder with your key. Get a free API key or rank your own CVEs.
Data as of 7 Oct 2026, 05:16 UK time