CVE-2025-54313

Published
View on NVD ↗
CVSS v3
7.5
HIGH
CVSS v2
N/A
Affected
2
PROJECTS

Description

eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Turns off all rules that are unnecessary or might conflict with Prettier.
NPMNPM
Turns off all rules that are unnecessary or might conflict with Prettier.
GitHubGitHub
5.89K