CVE Explorer
CVE-2026-48027
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
Known exploited
CISA KEV
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"nx-console","vendor":"nrwl","versions":[{"status":"affected","version":"= 18.95.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":9.3,"baseSeverity":"CRITICAL","privilegesRequired":"NONE","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"HIGH","vulnIntegrityImpact":"HIGH"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-506","description":"CWE-506: Embedded Malicious Code","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/problemTypes/0/descriptions/0
Known exploitation assertions
2 source assertions{"cwes":["CWE-506"],"dateAdded":"2026-05-27","dueDate":"2026-06-10","knownRansomwareCampaignUse":"Known","notes":"This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027","product":"Nx Console","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of th…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:3e3d8521df58467b9adc6bea225dadc3fde777a43185b57d19a8625e3f4be311 · sha256:16acee8334e59e44… · /vulnerabilities/51Open source location →
{"cwes":["CWE-506"],"dateAdded":"2026-05-27","dueDate":"2026-06-10","knownRansomwareCampaignUse":"Known","notes":"This vulnerability could affect an open-source component, third-party library, protocol, or proprietary implementation that could be used by different products. For more information, please see: https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w ; https://nvd.nist.gov/vuln/detail/CVE-2026-48027","product":"Nx Console","requiredAction":"Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of th…
- cisa_kev_jsonknown_exploitedurn:baitaphish:normalized-source-record:v2:efb1e9c59b3697d80afa0df44b8ebf62d8fa0ba30e33f0ca1dad722b755e4d18 · sha256:635dff916c4092c0… · /vulnerabilities/54Open source location →
Source references
5 source assertions{"name":"https://github.com/nrwl/nx-console/issues/3139","tags":["x_refsource_MISC"],"url":"https://github.com/nrwl/nx-console/issues/3139"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/references/1
{"name":"https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w","tags":["x_refsource_CONFIRM"],"url":"https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/references/0
{"name":"https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise","tags":["x_refsource_MISC"],"url":"https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/references/2
{"tags":["government-resource"],"url":"https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/adp/0/references/0
{"name":"https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised","tags":["x_refsource_MISC"],"url":"https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:90d8e2f42a817095ae4521f47e8d322d1ed1470578549ab22b2f21b73f20d624 · sha256:3f692344fbbef406… · /containers/cna/references/3
Attribution and limitations
- CISA Known Exploited Vulnerabilities JSON: CISA named for provenance; do not use CISA/DHS marks or imply endorsement Source →
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.