StackRadar

CVE-2026-50289

High

Advisory

Published 15 Jul 2026In the index since 5 Sept 2026
Severity
High
worst across findings
CVSS
8.7
base score, highest
EPSS
0.022
81st percentile
CISA KEV
Not listed
no confirmed exploitation
Charts affected
44
of 17,781 indexed, latest versions
Container images
42
deployed by those charts
Fix available
1 of 1
affected package

systeminformation: OS command injection in networkInterfaces() via interfaces(5) source-directive path on Linux

Carried by container images the latest versions of 44 of 17,781 indexed charts deploy, on 42 images.

Affected packageAffected versionsFixed inImages
systeminformationnpm3.54.0, 4.26.10, 4.34.9, 5.7.6+29 more5.31.742
OSV records
GHSA-5xpp-75jx-m839

Charts affected

44 by stars
ChartLatestAffected imagesRadar Score
difydoubanVerified publisher0.10.01 of 6See more

dify douban 0.10.0

1 of the 6 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
langgenius/dify-web:1.10.1-fix.1c306ac577912
systeminformation@5.27.12
5.31.7

Open the chart page →

19,391
sorry-cypresssorry-cypressVerified publisher1.20.01 of 4See more

sorry-cypress sorry-cypress 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
systeminformation@5.21.8
5.31.7

Open the chart page →

4,285
backstagerhdh-chartVerified publisher4.0.11 of 2See more

backstage rhdh-chart 4.0.1

1 of the 2 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
systeminformation@5.31.6
5.31.7

Open the chart page →

1,339
misskeyalytiVerified publisher1.0.01 of 1See more

misskey alyti 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
misskey/misskey:12.110.1e08b7c478093
systeminformation@5.11.9
5.31.7

Open the chart page →

5,251
codetogethercodetogether1.4.251 of 1See more

codetogether codetogether 1.4.25

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
codetogether/codetogether:latest4348c8a38752
systeminformation@5.23.3
5.31.7

Open the chart page →

7,450
kobotoolboxone-acre-fundVerified publisher0.7.41 of 9See more

kobotoolbox one-acre-fund 0.7.4

1 of the 9 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
enketo/enketo-express:3.0.4dcad9c2273f6
systeminformation@5.9.9
5.31.7

Open the chart page →

18,517
browserless-chromesagikazarmarkVerified publisher0.0.51 of 1See more

browserless-chrome sagikazarmark 0.0.5

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
systeminformation@5.8.7
5.31.7

Open the chart page →

24,488
soketisoketi2.0.01 of 1See more

soketi soketi 2.0.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
quay.io/soketi/soketi:1.6-16-debian713223456cf1
systeminformation@5.12.13
5.31.7

Open the chart page →

1,636
directusdirectus-io2.1.01 of 3See more

directus directus-io 2.1.0

1 of the 3 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
directus/directus:12.0.29c8470ea465c
systeminformation@5.31.6
5.31.7

Open the chart page →

7,473
joplin-serverdjjudas21Verified publisher5.5.81 of 1See more

joplin-server djjudas21 5.5.8

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
joplin/server:2.14.2-betab87564ef34e9
systeminformation@5.21.15
5.31.7

Open the chart page →

3,925
ranetogabisonfire0.1.21 of 1See more

raneto gabisonfire 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
systeminformation@4.34.9
5.31.7

Open the chart page →

2,519
ghostgeek-cookbookVerified publisher2.2.01 of 1See more

ghost geek-cookbook 2.2.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:4.37.0767230c0f263
systeminformation@5.9.3
5.31.7

Open the chart page →

4,260
homebridgegeek-cookbookVerified publisher5.3.21 of 1See more

homebridge geek-cookbook 5.3.2

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
systeminformation@5.11.14
5.31.7

Open the chart page →

15,653
immichimmich-helm0.3.01 of 4See more

immich immich-helm 0.3.0

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
systeminformation@5.23.8
5.31.7

Open the chart page →

15,712
difykubeblocksVerified publisher0.5.11 of 5See more

dify kubeblocks 0.5.1

1 of the 5 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
langgenius/dify-web:0.6.11a2a294743634
systeminformation@5.22.11
5.31.7

Open the chart page →

20,403
chibisafel4gVerified publisher0.1.11 of 3See more

chibisafe l4g 0.1.1

1 of the 3 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
chibisafe/chibisafe-server:latest3da4fcbc1a18
systeminformation@5.22.7
5.31.7

Open the chart page →

5,654
supabasesupabse0.8.01 of 11See more

supabase supabse 0.8.0

1 of the 11 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
supabase/storage-api:v1.60.4c8eb9858eafe
systeminformation@5.31.2
5.31.7

Open the chart page →

18,075
tdarrvhdirkVerified publisher5.0.51 of 2See more

tdarr vhdirk 5.0.5

1 of the 2 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
haveagitgat/tdarr_node:2.17.013ff0913202dd
systeminformation@5.18.3
5.31.7

Open the chart page →

26,657
youtubedl-materialyoutubedl-materialVerified publisher0.0.11 of 1See more

youtubedl-material youtubedl-material 0.0.1

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:latest2f943d584711
systeminformation@5.17.13
5.31.7

Open the chart page →

9,783
ghostchart-ghost0.1.51 of 2See more

ghost chart-ghost 0.1.5

1 of the 2 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:6.22.0-alpine3.23ac533a6988ee
systeminformation@5.30.2
5.31.7

Open the chart page →

4,083
authfcryptexlabsVerified publisher0.12.131 of 4See more

authf cryptexlabs 0.12.13

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
cryptexlabs/authf:0.12.11189c07411d7c
systeminformation@5.22.9
5.31.7

Open the chart page →

3,769
difydify1.0.01 of 4See more

dify dify 1.0.0

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
langgenius/dify-web:1.0.0d64914ff0d6d
systeminformation@5.25.11
5.31.7

Open the chart page →

19,224
directusdirectusVerified publisher0.9.101 of 4See more

directus directus 0.9.10

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
directus/directus:11.1.0e3c8bb975350
systeminformation@5.23.5
5.31.7

Open the chart page →

4,551
shinobigeek-cookbookVerified publisher1.2.21 of 1See more

shinobi geek-cookbook 1.2.2

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
shinobisystems/shinobi:dev3ca746937856
systeminformation@5.7.8
5.31.7

Open the chart page →

4,591
ghostghostVerified publisher0.1.01 of 4See more

ghost ghost 0.1.0

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:5.79.083f7bf209844
systeminformation@5.21.11
5.31.7

Open the chart page →

9,019
indexer-chartindexer-application0.1.01 of 1See more

indexer-chart indexer-application 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
ibarreche/cloud-indexer-ci:latestb7a08274e69f
systeminformation@5.11.14
5.31.7

Open the chart page →

3,289
ghostjanip81-helm-chartsVerified publisher0.1.21 of 1See more

ghost janip81-helm-charts 0.1.2

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:6.37.01ef2e532ca4d
systeminformation@5.31.5
5.31.7

Open the chart page →

3,436
ghostk8s-home-lab-repo4.1.01 of 1See more

ghost k8s-home-lab-repo 4.1.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:6.41.129773d6be407
systeminformation@5.31.6
5.31.7

Open the chart page →

3,092
shinobik8s-home-lab-repo2.1.11 of 1See more

shinobi k8s-home-lab-repo 2.1.1

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
shinobisystems/shinobi:latestc2f5ce2e1067
systeminformation@5.7.6
5.31.7

Open the chart page →

4,667
youtubedl-materialk8s-home-lab-repo5.1.11 of 1See more

youtubedl-material k8s-home-lab-repo 5.1.1

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
tzahi12345/youtubedl-material:4.3.22f943d584711
systeminformation@5.17.13
5.31.7

Open the chart page →

9,783
aperagkubeblocksVerified publisher0.0.0-nightly1 of 3See more

aperag kubeblocks 0.0.0-nightly

1 of the 3 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
systeminformation@5.31.4
5.31.7

Open the chart page →

8,405
ghostkubernetes-homelab-helm-chartsVerified publisher0.1.21 of 2See more

ghost kubernetes-homelab-helm-charts 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:6.39.0-alpine77196da4b0df
systeminformation@5.31.6
5.31.7

Open the chart page →

2,756
homepagekubernetes-homelab-helm-chartsVerified publisher0.1.01 of 1See more

homepage kubernetes-homelab-helm-charts 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
systeminformation@5.30.8
5.31.7

Open the chart page →

1,378
sentence-collectormozilla0.1.21 of 2See more

sentence-collector mozilla 0.1.2

1 of the 2 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
mozilla/sentencecollector:2.0.91da6ff5c4895
systeminformation@4.26.10
5.31.7

Open the chart page →

6,684
ghostmt1905028.25.11 of 3See more

ghost mt190502 8.25.1

1 of the 3 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
library/ghost:6.25.12654b1e90413
systeminformation@5.31.5
5.31.7

Open the chart page →

4,960
openwhiskopenwhisk1.0.01 of 10See more

openwhisk openwhisk 1.0.0

1 of the 10 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
openwhisk/alarmprovider:2.2.0b695a6ceb406
systeminformation@3.54.0
5.31.7

Open the chart page →

36,215
readability-js-serverreadability-js-server0.1.01 of 1See more

readability-js-server readability-js-server 0.1.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
phpdockerio/readability-js-server:1.8.0ea8354b42600
systeminformation@5.30.0
5.31.7

Open the chart page →

1,858
joplinrubxkubeVerified publisher1.3.11 of 2See more

joplin rubxkube 1.3.1

1 of the 2 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
joplin/server:3.0-beta52af57880c0e
systeminformation@5.21.15
5.31.7

Open the chart page →

7,413
sorry-cypresssoftonic1.20.01 of 4See more

sorry-cypress softonic 1.20.0

1 of the 4 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
agoldis/sorry-cypress-director:2.5.1110228ecd353b
systeminformation@5.21.8
5.31.7

Open the chart page →

4,285
retail-store-sample-checkout-chartstacksimplifyVerified publisher1.0.01 of 1See more

retail-store-sample-checkout-chart stacksimplify 1.0.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
systeminformation@5.23.8
5.31.7

Open the chart page →

1,313
lodestar-validatorstakewise1.2.01 of 1See more

lodestar-validator stakewise 1.2.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
chainsafe/lodestar:v1.27.07b9fe4aa8073
systeminformation@5.23.8
5.31.7

Open the chart page →

4,052
trudesktechpreta1.0.01 of 3See more

trudesk techpreta 1.0.0

1 of the 3 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
polonel/trudesk:1.2.60cf6513f6fe3
systeminformation@5.7.7
5.31.7

Open the chart page →

4,017
browserlessvictorlane0.2.01 of 1See more

browserless victorlane 0.2.0

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
systeminformation@5.31.4
5.31.7

Open the chart page →

4,305
sirenwateim1.0.21 of 1See more

siren wateim 1.0.2

1 of the 1 container images this version deploys carry CVE-2026-50289.

Container imageDigestPackageFixed in
sigp/siren:v3.0.42c219b04758e
systeminformation@5.27.7
5.31.7

Open the chart page →

5,984

Container images carrying it

42 by charts deploying them

A fixed version is listed for 1 of the 1 affected package.

Container imageDigestPackageFixed inUsed by
agoldis/sorry-cypress-director:2.5.1110228ecd353b
systeminformation@5.21.8
5.31.7
2
tzahi12345/youtubedl-material:4.3.2:latest2f943d584711
systeminformation@5.17.13
5.31.7
2
apecloud/aperag-frontend:v0.0.0-nightlyb3ae37840ace
systeminformation@5.31.4
5.31.7
1
browserless/chrome:1.48.0-chrome-stablec81ae5585b47
systeminformation@5.8.7
5.31.7
1
chainsafe/lodestar:v1.27.07b9fe4aa8073
systeminformation@5.23.8
5.31.7
1
chibisafe/chibisafe-server:latest3da4fcbc1a18
systeminformation@5.22.7
5.31.7
1
codetogether/codetogether:latest4348c8a38752
systeminformation@5.23.3
5.31.7
1
cryptexlabs/authf:0.12.11189c07411d7c
systeminformation@5.22.9
5.31.7
1
directus/directus:12.0.29c8470ea465c
systeminformation@5.31.6
5.31.7
1
directus/directus:11.1.0e3c8bb975350
systeminformation@5.23.5
5.31.7
1
enketo/enketo-express:3.0.4dcad9c2273f6
systeminformation@5.9.9
5.31.7
1
haveagitgat/tdarr_node:2.17.013ff0913202dd
systeminformation@5.18.3
5.31.7
1
ibarreche/cloud-indexer-ci:latestb7a08274e69f
systeminformation@5.11.14
5.31.7
1
joplin/server:3.0-beta52af57880c0e
systeminformation@5.21.15
5.31.7
1
joplin/server:2.14.2-betab87564ef34e9
systeminformation@5.21.15
5.31.7
1
langgenius/dify-web:0.6.11a2a294743634
systeminformation@5.22.11
5.31.7
1
langgenius/dify-web:1.10.1-fix.1c306ac577912
systeminformation@5.27.12
5.31.7
1
langgenius/dify-web:1.0.0d64914ff0d6d
systeminformation@5.25.11
5.31.7
1
library/ghost:6.37.01ef2e532ca4d
systeminformation@5.31.5
5.31.7
1
library/ghost:6.25.12654b1e90413
systeminformation@5.31.5
5.31.7
1
library/ghost:6.41.129773d6be407
systeminformation@5.31.6
5.31.7
1
library/ghost:4.37.0767230c0f263
systeminformation@5.9.3
5.31.7
1
library/ghost:6.39.0-alpine77196da4b0df
systeminformation@5.31.6
5.31.7
1
library/ghost:5.79.083f7bf209844
systeminformation@5.21.11
5.31.7
1
library/ghost:6.22.0-alpine3.23ac533a6988ee
systeminformation@5.30.2
5.31.7
1
misskey/misskey:12.110.1e08b7c478093
systeminformation@5.11.9
5.31.7
1
mozilla/sentencecollector:2.0.91da6ff5c4895
systeminformation@4.26.10
5.31.7
1
openwhisk/alarmprovider:2.2.0b695a6ceb406
systeminformation@3.54.0
5.31.7
1
phpdockerio/readability-js-server:1.8.0ea8354b42600
systeminformation@5.30.0
5.31.7
1
polonel/trudesk:1.2.60cf6513f6fe3
systeminformation@5.7.7
5.31.7
1
shinobisystems/shinobi:dev3ca746937856
systeminformation@5.7.8
5.31.7
1
shinobisystems/shinobi:latestc2f5ce2e1067
systeminformation@5.7.6
5.31.7
1
sigp/siren:v3.0.42c219b04758e
systeminformation@5.27.7
5.31.7
1
supabase/storage-api:v1.60.4c8eb9858eafe
systeminformation@5.31.2
5.31.7
1
ghcr.io/browserless/chromium:v2.43.0853e6f105b51
systeminformation@5.31.4
5.31.7
1
ghcr.io/gethomepage/homepage:v1.13.1d8d784e50901
systeminformation@5.30.8
5.31.7
1
ghcr.io/immich-app/immich-server:v2.3.1f8d06a32b1b2
systeminformation@5.23.8
5.31.7
1
ghcr.io/linuxserver/raneto:version-0.16.6ef768f3df5d0
systeminformation@4.34.9
5.31.7
1
ghcr.io/oznu/homebridge:2022-07-08ff2af53897e7
systeminformation@5.11.14
5.31.7
1
public.ecr.aws/aws-containers/retail-store-sample-checkout:1.3.0687aa68dd490
systeminformation@5.23.8
5.31.7
1
quay.io/rhdh/rhdh-hub-rhel9:latest0b26358f5793
systeminformation@5.31.6
5.31.7
1
quay.io/soketi/soketi:1.6-16-debian713223456cf1
systeminformation@5.12.13
5.31.7
1

syft 1.42.1 · advisories as of 14 Sept 2026

Corrections: contact@stackradar.io

Catalogue: Artifact Hub · Advisories: OSV · Exploitation: FIRST EPSS, CISA KEV.