CVE-2025-54313

EUVD-2025-21972
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
mitreCNA
7.5 HIGH
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 91%
Affected Products (NVD)
VendorProductVersion
prettiereslint-config-prettier
8.10.1
prettiereslint-config-prettier
9.1.1
prettiereslint-config-prettier
10.1.6
prettiereslint-config-prettier
10.1.7
prettiereslint-plugin-prettier
4.2.2
prettiereslint-plugin-prettier
4.2.3
un-tssynckit
0.11.9
un-tspkgr\/core
0.2.8
alexghrgot-fetch
5.1.1
alexghrgot-fetch
5.1.2
un-tsnapi-postinstall
0.3.1
homarrhomarr
1.29.0 ≤
𝑥
< 1.30.0
𝑥
= Vulnerable software versions