CRITICAL

CVE-2026-48027

Nx Nx Console 2026-05-27 CVSS v3.1
CVSS
9.8
KEV

Description

Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.

Summary dbcve.org

This is a supply chain attack where a malicious version (18.95.0) of the Nx Console VS Code extension was published to Visual Studio Marketplace and OpenVSX. The compromised version was available for approximately 18-36 minutes before being removed. The malicious version could have allowed arbitrary code execution or data exfiltration through the VS Code extension's privileges.

Mitigation

Users who installed Nx Console version 18.95.0 during the affected window should immediately upgrade to version 18.100.0 and review extension permissions and network activity for signs of compromise.

Proof of Concept

Weakness (CWE)

CWE-506

EPSS Score

1.85%
Probability of exploitation in next 30 days
78.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE