CVE-2026-48027
About
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
Rainforest analyst review
This is not a code flaw but a software supply-chain compromise: on 19 May 2026 a malicious build of the Nx Console extension, version 18.95.0, was published to the Visual Studio Marketplace and OpenVSX. It was live for roughly 18 minutes on the Marketplace and about 36 on OpenVSX before removal, but anyone who installed or auto-updated in those windows received attacker-controlled code that ran with the developer's privileges inside their editor. The malicious version is flagged as embedded malicious functionality, not a bug to be triggered.
Nx Console is a popular IDE extension for the Nx and Lerna build tooling, so the victims are developers, and code running in a developer's environment can read source, tokens, SSH keys, and cloud credentials and pivot into CI/CD, the pattern of recent editor-extension and npm supply-chain attacks. The brief exposure window limits the blast radius but does not eliminate it. Upgrade to the clean 18.100.0, since 18.95.0 is the only compromised build. Anyone who may have run the malicious version should rotate credentials and tokens present on the machine and review for unauthorized access, because patching does not undo secrets already exfiltrated.
References
- https://github.com/nrwl/nx-console/issues/3139
- https://github.com/nrwl/nx-console/security/advisories/GHSA-c9j4-9m59-847w
- https://nx.dev/blog/nx-console-v18-95-0-postmortem#indicators-of-compromise
- https://www.stepsecurity.io/blog/nx-console-vs-code-extension-compromised
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-48027
Related CVEs
No related CVEs.
Frequently asked questions
What is CVE-2026-48027?
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes).
How severe is CVE-2026-48027?
CVE-2026-48027 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2026-48027 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2026-48027?
Public advisories list the following as affected: nx console. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2026-48027?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
