{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-08-04T22:45:42.357","vulnerabilities":[{"cve":{"id":"CVE-2025-54313","sourceIdentifier":"cve@mitre.org","published":"2025-07-19T17:15:23.733","lastModified":"2026-06-17T09:39:49.897","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows."},{"lang":"es","value":"eslint-config-prettier 8.10.1, 9.1.1, 10.1.6 y 10.1.7 contiene código malicioso que compromete la cadena de suministro. Al instalar un paquete afectado, se ejecuta un archivo install.js que lanza el malware node-gyp.dll en Windows."}],"affected":[{"source":"cve@mitre.org","affectedData":[{"vendor":"prettier","product":"eslint-config-prettier","defaultStatus":"unaffected","versions":[{"version":"8.10.1","versionType":"semver","status":"affected"},{"version":"9.1.1","versionType":"semver","status":"affected"},{"version":"10.1.6","versionType":"semver","status":"affected"},{"version":"10.1.7","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"cve@mitre.org","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"NONE"},"exploitabilityScore":2.2,"impactScore":4.7}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2026-01-23T04:55:19.677903Z","id":"CVE-2025-54313","options":[{"exploitation":"active"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"cisaExploitAdd":"2026-01-22","cisaActionDue":"2026-02-12","cisaRequiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.","cisaVulnerabilityName":"Prettier eslint-config-prettier Embedded Malicious Code Vulnerability","weaknesses":[{"source":"cve@mitre.org","type":"Secondary","description":[{"lang":"en","value":"CWE-506"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:prettier:eslint-config-prettier:8.10.1:*:*:*:*:node.js:*:*","matchCriteriaId":"B43B0C8D-0662-45E9-ADA9-AA6A8A5AC042"},{"vulnerable":true,"criteria":"cpe:2.3:a:prettier:eslint-config-prettier:9.1.1:*:*:*:*:node.js:*:*","matchCriteriaId":"9CAD3812-C7C4-443C-BFFE-3B7751EBCB38"},{"vulnerable":true,"criteria":"cpe:2.3:a:prettier:eslint-config-prettier:10.1.6:*:*:*:*:node.js:*:*","matchCriteriaId":"64749F3A-C896-4133-8C21-4C2439780CB0"},{"vulnerable":true,"criteria":"cpe:2.3:a:prettier:eslint-config-prettier:10.1.7:*:*:*:*:node.js:*:*","matchCriteriaId":"C9CE9AC7-568C-43CF-8417-ADA21CECB3A5"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:prettier:eslint-plugin-prettier:4.2.2:*:*:*:*:node.js:*:*","matchCriteriaId":"3A8983B4-86E8-4B13-95A1-EEF13107122B"},{"vulnerable":true,"criteria":"cpe:2.3:a:prettier:eslint-plugin-prettier:4.2.3:*:*:*:*:node.js:*:*","matchCriteriaId":"F22A30A9-BA7F-4B49-8C9B-547E79F1CD46"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:un-ts:synckit:0.11.9:*:*:*:*:node.js:*:*","matchCriteriaId":"92E47D68-A074-4FFD-8A7C-91BC032A95E1"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:un-ts:pkgr\\/core:0.2.8:*:*:*:*:node.js:*:*","matchCriteriaId":"CDB0E59B-E301-4686-88E0-A107B823FE77"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:alexghr:got-fetch:5.1.1:*:*:*:*:node.js:*:*","matchCriteriaId":"9839FE3B-999A-4CA8-AE29-C6854B13A1FD"},{"vulnerable":true,"criteria":"cpe:2.3:a:alexghr:got-fetch:5.1.2:*:*:*:*:node.js:*:*","matchCriteriaId":"6AA8D543-56F5-438E-B99B-ECD89642C416"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:un-ts:napi-postinstall:0.3.1:*:*:*:*:node.js:*:*","matchCriteriaId":"044AD411-E619-4FAE-8506-3C44FBBC5666"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:homarr:homarr:*:*:*:*:*:*:*:*","versionStartIncluding":"1.29.0","versionEndExcluding":"1.30.0","matchCriteriaId":"F3427958-A7B3-4FBA-A8D8-7F04C04E5F2F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://github.com/prettier/eslint-config-prettier/issues/339","source":"cve@mitre.org","tags":["Issue Tracking"]},{"url":"https://news.ycombinator.com/item?id=44608811","source":"cve@mitre.org","tags":["Issue Tracking"]},{"url":"https://news.ycombinator.com/item?id=44609732","source":"cve@mitre.org","tags":["Issue Tracking"]},{"url":"https://socket.dev/blog/npm-phishing-campaign-leads-to-prettier-tooling-packages-compromise","source":"cve@mitre.org","tags":["Third Party Advisory"]},{"url":"https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.npmjs.com/package/eslint-config-prettier?activeTab=versions","source":"cve@mitre.org","tags":["Product"]},{"url":"https://www.stepsecurity.io/blog/supply-chain-security-alert-eslint-config-prettier-package-shows-signs-of-compromise","source":"cve@mitre.org","tags":["Exploit","Third Party Advisory"]},{"url":"https://github.com/community-scripts/ProxmoxVE/discussions/6115","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.endorlabs.com/learn/cve-2025-54313-eslint-config-prettier-compromise----high-severity-but-windows-only","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.bleepingcomputer.com/news/security/popular-npm-linter-packages-hijacked-via-phishing-to-drop-malware/","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["Exploit","Third Party Advisory"]},{"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-54313","source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","tags":["US Government Resource"]}]}}]}