Summary
The System Information Library for Node.JS (npm package "systeminformation") has a command injection vulnerability that, when successfully exploited, could lead to disclosure of sensitive information, addition or modification of data, or Denial of Service (DoS).
Please see the full security advisory article here for more details and updates.