HIGH · 7.5

CVE-2025-54313

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gy...

Vulnerability Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
PrettierEslint-Config-Prettier8.10.1
MicrosoftWindows-
PrettierEslint-Plugin-Prettier4.2.2
Un-TsSynckit0.11.9
Un-TsPkgr\/Core0.2.8
AlexghrGot-Fetch5.1.1
Un-TsNapi-Postinstall0.3.1
HomarrHomarr>= 1.29.0, < 1.30.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-54313?

CVE-2025-54313 is a vulnerability with a CVSS score of 7.5 (HIGH). eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gy...

How severe is CVE-2025-54313?

CVE-2025-54313 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2025-54313?

Check the references section above for vendor advisories and patch information. Affected products include: Prettier Eslint-Config-Prettier, Microsoft Windows, Prettier Eslint-Plugin-Prettier, Un-Ts Synckit, Un-Ts Pkgr\/Core.