Vulnerabilities

CVE-2026-48027

Nx Console Embedded Malicious Code Vulnerability

Actively exploited (CISA KEV) Used in ransomware campaigns Critical 9.8 CVSS 3.1

Description

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.

Description as published by the source, in English.

Key facts

Published
2026-05-27
Last modified
2026-06-17
Assigned by
security-advisories@github.com
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Scored by
nvd@nist.gov (NVD Primary)
Probability of exploitation
1.9 % higher than 77 % of all known vulnerabilities
EPSS, next 30 days, model v2026.06.15
Fix available
Not registered in the sources

Actively exploited

CISA added this vulnerability to the Known Exploited Vulnerabilities catalogue on 2026-05-27, with a remediation deadline of 2026-06-10 for US federal agencies.

Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Affected products

Vendor Product Versions Status
Nx Nx Console 18.95.0 Affected

Weakness type

Attack techniques

Derived through the weakness type: CVE to CWE to CAPEC to ATT&CK. This shows which techniques the weakness class is historically used for. It does not assert that this vulnerability has been exploited that way.

  • T1001.002: Steganography command-and-control
  • T1027.003: Steganography stealth
  • T1027.004: Compile After Delivery stealth
  • T1027.009: Embedded Payloads stealth
  • T1195.001: Compromise Software Dependencies and Development Tools initial-access
  • T1195.002: Compromise Software Supply Chain initial-access
  • T1218.001: Compiled HTML File stealth
  • T1221: Template Injection stealth

References

Does this affect you?

A vulnerability matters only if you run the product, in an affected version, somewhere an attacker can reach.

Check your asset list Browse all vulnerabilities