CVE-2025-54313

unknown KEV
Published 2025-07-19 · Modified 2026-01-22
CVSS v3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
CVSS v2
VIR risk
1.5

Description

Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CISA KEV

Vendor
Prettier
Product
eslint-config-prettier
Due date
2026-02-12

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://www.npmjs.com/package/eslint-config-prettier?activeTab=versions ; https://github.com/prettier/eslint-config-prettier/issues/339#issuecomment-3090304490 ; https://nvd.nist.gov/vuln/detail/CVE-2025-54313

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2025-54313.html

Exploits

OS impact

OSVersionStatusFixed in
suse slesaffected

Package impact

EcosystemPackageVulnerableFixed
npm npmeslint-config-prettier>=8.10.1,<8.10.28.10.2
npm npmeslint-config-prettier>=9.1.1,<9.1.29.1.2
npm npmeslint-config-prettier>=10.1.6,<10.1.810.1.8
npm npmeslint-plugin-prettier>=4.2.2,<4.2.44.2.4
npm npmsynckit>=0.11.9,<0.11.100.11.10
npm npm@pkgr/core>=0.2.8,<0.2.90.2.9
npm npmnapi-postinstall>=0.3.1,<0.3.20.3.2
npm npmgot-fetch>=5.1.11,<6.0.06.0.0

References

Verify integrity in audit chain (admin only). AS-IS.