Skip to content

Critical Vulnerability in Popular Node.js Library Exposes Windows Systems to RCE Attacks

Cybersecuritynews •Abinaya • December 18, 2025

A serious security flaw has been discovered in systeminformation, a popular Node.js library used by thousands of developers. The vulnerability, labelled CVE-2025-68154, allows attackers to run malicious code on Windows computers. All versions up to 5.27.13 are affected, and developers must update to version 5.27.14 immediately. Systeminformation is a widely-used Node.js package that helps developers […]

Extracted Entities

Attack Types (1)

Platforms (1)

Tools (1)