← Back

CVE-2025-54313

nvd nist
Published: Jul 19, 2025Modified: Jun 17, 2026CISA KEV

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Exploitability: 2.2 / Impact: 4.7
Source: MITRE (Secondary)

Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Affected (12)

Show all products
2 products
Eslint Config Prettier
Eslint Plugin Prettier
3 products
Synckit
Pkgr/core
Napi Postinstall
1 product
Got Fetch
1 product
Homarr
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Prettier
Version 10.1.6
Version 10.1.7
Version 8.10.1
Version 9.1.1
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Prettier
Version 4.2.2
Version 4.2.3
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.11.9
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.2.8
Configuration E
2 vulnerable
Vulnerable SoftwareAffected Versions
Alexghr
Version 5.1.1
Version 5.1.2
Configuration F
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 0.3.1
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
From 1.29.0 to 1.30.0
Running on/withPlatform Versions
Microsoft
Windows
All versions

Timeline

No history available yet.