CISA Known Exploited Vulnerability

CVE-2025-54313

Prettier · eslint-config-prettier

Prettier eslint-config-prettier Embedded Malicious Code Vulnerability

Date added
BOD 22-01 due date
CWE CWE-506
Ransomware Unknown

CISA description

Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.

Required action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.