ThreatCluster

Critical Vulnerability in Node.js Library Allows RCE on Windows Systems

First seen 18 Dec 2025, 10:54 UTC GbhackersCybersecuritynews 66

Article Content

Browse articles
ThreatCluster

A critical vulnerability, CVE-2025-68154, has been identified in the systeminformation Node.js library, affecting all versions up to 5.27.13. This flaw enables attackers to execute remote commands on Windows systems, prompting developers to update to version 5.27.14 immediately to mitigate risks.