CVE record
CVE-2025-54313
Prettier eslint-config-prettier Embedded Malicious Code Vulnerability
Prettier eslint-config-prettier contains an embedded malicious code vulnerability. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
high
CVSS 7.5 · CVSS_V3
Affected packages
6
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- Prettier
- Product
- eslint-config-prettier
- Date added
- Jan 22, 2026
- CISA federal remediation due date
- Feb 12, 2026
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Known ransomware campaign use
- Unknown
- CWE
- CWE-506
OSV package mapping
Affected open-source packages
| Package | Ecosystem | Fixed versions |
|---|---|---|
| eslint-config-prettier | npm | 8.10.2, 9.1.2, 10.1.8 |
| eslint-plugin-prettier | npm | 4.2.4 |
| synckit | npm | 0.11.10 |
| @pkgr/core | npm | 0.2.9 |
| napi-postinstall | npm | 0.3.2 |
| got-fetch | npm | 6.0.0 |