CVE-2026-48027
Compromised Nx Console version 18.95.0
Description
Nx Console is the user interface for Nx & Lerna. On 19 May 2026, a malicious version of Nx Console, 18.95.0, was published at 12:30 PM UTC and removed soon after at 12:48 PM UTC, leaving it available for ~18 minutes in Visual Studio Marketplace. For OpenVSX, the problem was detected later, and the compromised version was available from 12:33 UTC to 13:09 UTC (~36 minutes). Version 18.100.0 of Nx Console is not compromised and users may remediate by upgrading to that version.
In plain language
AI Act nowCVE-2026-48027 is a serious incident where a bad Nx Console download (version 18.95.0) was published briefly and could let attackers run code on your computer without logging in—if you installed that exact version, you should act now.
CVE-2026-48027 is a supply-chain compromise: a malicious Nx Console 18.95.0 package was briefly published to Visual Studio Marketplace/OpenVSX and enables unauthenticated remote attackers to achieve arbitrary code execution on affected installs.
What to do now
- Check whether your systems have Nx Console installed and specifically whether the installed version is 18.95.0.
- If you are on Nx Console 18.95.0, immediately upgrade to Nx Console 18.100.0.
- Follow the vendor’s postmortem/indicators-of-compromise steps to check for compromise on any machines where 18.95.0 was installed.
- If you cannot confirm you are clean or cannot upgrade right away, stop using Nx Console until mitigations are applied as instructed by the vendor; if mitigations are unavailable, discontinue use.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
References
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-48027 and every CVE in our database. Create a free account — no credit card required.
Create Free Account