Malicious Code Injection in Nx Console by Nx and Lerna
CVE-2026-48027

9.3CRITICAL

Key Information:

Vendor

Nrwl

Vendor
CVE Published:
27 May 2026

What is CVE-2026-48027?

On May 19, 2026, a malicious version of the Nx Console application, version 18.95.0, was briefly available on Visual Studio Marketplace for around 18 minutes before it was removed. This compromised version contained harmful code that could affect users' systems, presenting a serious security risk. In OpenVSX, this vulnerability was detected more recently, with the compromised version available for approximately 36 minutes. Users are advised to upgrade to version 18.100.0, which has been confirmed as secure, to protect against any potential threats associated with this incident.

Affected Version(s)

nx-console = 18.95.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.