← Back to CVE List
Vulnerability Intelligence Report
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

CVE-2025-54313

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CISA KEV SSVC: Active Exploitation
CVSS Base Score
7.5
HIGH
Exploitability:2.3
Impact Score:4.8
EPSS Probability:4.15%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-506 ↗CWE-506 Embedded Malicious Code

Affected Products & Versions

Vendor Product Affected Versions
prettier eslint-config-prettier 8.10.1 (affected), 9.1.1 (affected), 10.1.6 (affected), 10.1.7 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

CISA KEV
ACTIVE IN CATALOG
EPSS Score
4.146%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityMITRE Corporation · N/A · USA
Reserved2025-07-19T00:00:00
Published2025-07-19T00:00:00
Last Updated2026-02-26T17:50:26

LINK COPIED TO CLIPBOARD