CVE-2025-54313
EUVD-2025-2197219.07.2025, 17:15
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| prettier | eslint-config-prettier | 8.10.1 |
| prettier | eslint-config-prettier | 9.1.1 |
| prettier | eslint-config-prettier | 10.1.6 |
| prettier | eslint-config-prettier | 10.1.7 |
| prettier | eslint-plugin-prettier | 4.2.2 |
| prettier | eslint-plugin-prettier | 4.2.3 |
| un-ts | synckit | 0.11.9 |
| un-ts | pkgr\/core | 0.2.8 |
| alexghr | got-fetch | 5.1.1 |
| alexghr | got-fetch | 5.1.2 |
| un-ts | napi-postinstall | 0.3.1 |
| homarr | homarr | 1.29.0 ≤ 𝑥 < 1.30.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References