CyberSec.Space Logo
CVEブラウザに戻る

CVE-2025-54313

🔥 Known Exploited (CISA KEV)HIGH
7.5
CVSS Severity Score
EPSS Score0.0000%
EPSS Percentile0.00th
Published2025-07-19
Last Modified2026-06-17
Data SourcesNVDCISA KEV

Vulnerability Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Affected Platforms (CPE)

📦
Prettier

Eslint Config Prettier

= 8.10.1= 9.1.1= 10.1.6= 10.1.7
📦
Prettier

Eslint Plugin Prettier

= 4.2.2= 4.2.3
📦
Un Ts

Synckit

= 0.11.9
📦
Un Ts

Pkgr\/core

= 0.2.8

References & Advisories

関連する脆弱性情報