Description

Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's accounts.

INFO

Published Date :

2025-09-24T21:20:31.242Z

Last Modified :

2025-11-20T07:26:10.947Z

Source :

redhat
AFFECTED PRODUCTS

The following products are affected by CVE-2025-10894 vulnerability.

Vendors Products
Redhat
  • Acm
  • Ansible Automation Platform
  • Multicluster Globalhub
  • Serverless

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact