StackRadar

CVE-2026-26280

High

Advisory

Published 18 Feb 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.4
base score, highest
EPSS
0.012
67th percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
34
of 17,781 indexed, latest versions
Container images
32
deployed by those charts
Fix available
1 of 1
affected package

Systeminformation has a Command Injection via unsanitized interface parameter in wifi.js retry path

Carried by container images the latest versions of 34 of 17,781 indexed charts deploy, on 32 images.

Affected packageAffected versionsFixed inImages
systeminformationnpm3.54.0, 4.26.10, 4.34.9, 5.7.6+24 more5.30.832
OSV records
GHSA-9c88-49p5-5ggf

Charts affected

34 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
systeminformation@5.27.12
5.30.8

Open the chart page →

19,391
sorry-cypresssorry-cypressVerified publisher1.20.01 of 4See more

sorry-cypress sorry-cypress 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
systeminformation@5.21.8
5.30.8

Open the chart page →

4,285
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
systeminformation@5.11.9
5.30.8

Open the chart page →

5,251
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
systeminformation@5.23.3
5.30.8

Open the chart page →

7,450
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
systeminformation@5.9.9
5.30.8

Open the chart page →

18,517
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
systeminformation@5.8.7
5.30.8

Open the chart page →

24,488
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
systeminformation@5.12.13
5.30.8

Open the chart page →

1,636
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
systeminformation@5.21.15
5.30.8

Open the chart page →

3,925
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
systeminformation@4.34.9
5.30.8

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
systeminformation@5.9.3
5.30.8

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
systeminformation@5.11.14
5.30.8

Open the chart page →

15,653
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
systeminformation@5.23.8
5.30.8

Open the chart page →

15,712
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
systeminformation@5.22.11
5.30.8

Open the chart page →

20,403
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
systeminformation@5.22.7
5.30.8

Open the chart page →

5,654
tdarrvhdirkVerified publisher5.0.51 of 2See more

tdarr vhdirk 5.0.5

1 of the 2 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
systeminformation@5.18.3
5.30.8

Open the chart page →

26,657
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
systeminformation@5.17.13
5.30.8

Open the chart page →

9,783
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
systeminformation@5.30.2
5.30.8

Open the chart page →

4,083
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
systeminformation@5.22.9
5.30.8

Open the chart page →

3,769
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
systeminformation@5.25.11
5.30.8

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
systeminformation@5.23.5
5.30.8

Open the chart page →

4,551
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
systeminformation@5.7.8
5.30.8

Open the chart page →

4,591
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
systeminformation@5.21.11
5.30.8

Open the chart page →

9,019
indexer-chartindexer-application0.1.01 of 1See more

indexer-chart indexer-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
ibarreche/cloud-indexer-ci:latestb7a08274e69f
systeminformation@5.11.14
5.30.8

Open the chart page →

3,289
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
systeminformation@5.7.6
5.30.8

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
systeminformation@5.17.13
5.30.8

Open the chart page →

9,783
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
systeminformation@4.26.10
5.30.8

Open the chart page →

6,684
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
systeminformation@3.54.0
5.30.8

Open the chart page →

36,215
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
systeminformation@5.30.0
5.30.8

Open the chart page →

1,858
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
systeminformation@5.21.15
5.30.8

Open the chart page →

7,413
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
systeminformation@5.21.8
5.30.8

Open the chart page →

4,285
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
systeminformation@5.23.8
5.30.8

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
systeminformation@5.23.8
5.30.8

Open the chart page →

4,052
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
systeminformation@5.7.7
5.30.8

Open the chart page →

4,017
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-26280.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
systeminformation@5.27.7
5.30.8

Open the chart page →

5,984

Container images carrying it

32 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
agoldis/sorry-cypress-director:2.5.1110228ecd353b
systeminformation@5.21.8
5.30.8
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
systeminformation@5.17.13
5.30.8
2
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
systeminformation@5.8.7
5.30.8
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
systeminformation@5.23.8
5.30.8
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
systeminformation@5.22.7
5.30.8
1
codetogether/codetogether:latest4348c8a38752
systeminformation@5.23.3
5.30.8
1
cryptexlabs/authf:0.12.11189c07411d7c
systeminformation@5.22.9
5.30.8
1
directus/directus:11.1.0e3c8bb975350
systeminformation@5.23.5
5.30.8
1
enketo/enketo-express:3.0.4dcad9c2273f6
systeminformation@5.9.9
5.30.8
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
systeminformation@5.18.3
5.30.8
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
systeminformation@5.11.14
5.30.8
1
joplin/server:3.0-beta52af57880c0e
systeminformation@5.21.15
5.30.8
1
joplin/server:2.14.2-betab87564ef34e9
systeminformation@5.21.15
5.30.8
1
langgenius/dify-web:0.6.11a2a294743634
systeminformation@5.22.11
5.30.8
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
systeminformation@5.27.12
5.30.8
1
langgenius/dify-web:1.0.0d64914ff0d6d
systeminformation@5.25.11
5.30.8
1
library/ghost:4.37.0767230c0f263
systeminformation@5.9.3
5.30.8
1
library/ghost:5.79.083f7bf209844
systeminformation@5.21.11
5.30.8
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
systeminformation@5.30.2
5.30.8
1
misskey/misskey:12.110.1e08b7c478093
systeminformation@5.11.9
5.30.8
1
mozilla/sentencecollector:2.0.91da6ff5c4895
systeminformation@4.26.10
5.30.8
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
systeminformation@3.54.0
5.30.8
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
systeminformation@5.30.0
5.30.8
1
polonel/trudesk:1.2.60cf6513f6fe3
systeminformation@5.7.7
5.30.8
1
shinobisystems/shinobi:dev3ca746937856
systeminformation@5.7.8
5.30.8
1
shinobisystems/shinobi:latestc2f5ce2e1067
systeminformation@5.7.6
5.30.8
1
sigp/siren:v3.0.42c219b04758e
systeminformation@5.27.7
5.30.8
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
systeminformation@5.23.8
5.30.8
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
systeminformation@4.34.9
5.30.8
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
systeminformation@5.11.14
5.30.8
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
systeminformation@5.23.8
5.30.8
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
systeminformation@5.12.13
5.30.8
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.