CVE-2026-48027 KEV
9.8
CRITICAL · CVSS 3.1 · EPSS 1.3% (pctl 70)
Patch first
On CISA KEV — known exploited in the wild, due 2026-06-10.
Description
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 1.34% — more likely to be exploited than 70% of all CVEs |
| Weakness | CWE-506 |
| On CISA KEV | yes — remediate by 2026-06-10 |
| Public exploit | none known |
| Published | 2026-05-27 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Nx Console Embedded Malicious Code Vulnerability |
|---|---|
| Added | 2026-05-27 |
| Due | 2026-06-10 |
| Vendor / product | Nx / Nx Console |
| Ransomware use | known |
Affected (1)
| Vendor | Product |
|---|---|
| nx | nx console |
References
- https://github.com/nrwl/nx-console/issues/3139
- https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
- https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise
- https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027
→ the Explorer · watch your stack · NVD