CVE Database
/

CVE-2025-10894

Back to search

CVE-2025-10894

Published: Sep 24, 2025

Modified: Nov 20, 2025

PUBLISHED

CVSS v3.1

9.6

CRITICAL

Description

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

VendorProductVersions

Unknown

nx

affected
20.12.0
affected
21.8.0
affected
21.7.0
affected
20.11.0
affected
21.6.0

+3 more versions

Unknown

nx/devkit

affected
20.9.0
affected
21.5.0

Unknown

nx/enterprise-cloud

affected
3.2.0

Unknown

nx/eslint

affected
21.5.0

Unknown

nx/js

affected
20.9.0
affected
21.5.0

Unknown

nx/key

affected
3.2.0

Unknown

nx/node

affected
20.9.0
affected
21.5.0

Unknown

nx/workspace

affected
20.9.0
affected
21.5.0

Red Hat

Multicluster Global Hub

All versions

Red Hat

OpenShift Serverless

All versions

Red Hat

Red Hat Advanced Cluster Management for Kubernetes 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

High

Availability

High

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now