Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
History

Wed, 27 May 2026 20:45:00 +0000

Type Values Removed Values Added
First Time appeared Nx
Nx nx Console
CPEs cpe:2.3:a:nx:nx_console:18.95.0:*:*:*:*:visual_studio_code:*:*
Vendors & Products Nx
Nx nx Console
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 27 May 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 27 May 2026 17:45:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-05-27T00:00:00+00:00', 'dueDate': '2026-06-10T00:00:00+00:00'}


Wed, 27 May 2026 16:30:00 +0000

Type Values Removed Values Added
Description Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
Title Compromised Nx Console version 18.95.0
Weaknesses CWE-506
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-05-27T15:50:01.143Z

Updated: 2026-05-28T03:55:41.841Z

Reserved: 2026-05-20T17:44:09.587Z

Link: CVE-2026-48027

cve-icon Vulnrichment

Updated: 2026-05-27T17:49:49.453Z

cve-icon NVD

Status : Analyzed

Published: 2026-05-27T17:16:41.787

Modified: 2026-05-27T20:34:24.850

Link: CVE-2026-48027

cve-icon Redhat

No data.