Heavily used Node.js package has a code injection vulnerability

The heavily downloaded Node.js library “systeminformation” has a severe command injection vulnerability tracked as CVE-2021-21315. […]