Vulnerability record · CVE-2025-54782 · published 2 August 2025
CVE-2025-54782: NestJS devtools-integration unsafe sandbox allows remote code execution
Nestjs · Devtools Integration
The @nestjs/devtools-integration package (versions 0.2.0 and below) exposes a local development HTTP server whose /inspector/graph/interact endpoint runs attacker-supplied code in a Node.js vm.runInNewContext sandbox. The sandbox is unsafe and cross-origin protections are missing, so a developer visiting a malicious website can have arbitrary code executed on their local machine. It is fixed in version 0.2.1.
Description
Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an unsafe JavaScript sandbox (safe-eval-like implementation). Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine. The package adds HTTP endpoints to a locally running NestJS development server. One of these endpoints, /inspector/graph/interact, accepts JSON input containing a code field and executes the provided code in a Node.js vm.runInNewContext sandbox. This is fixed in version 0.2.1.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:
Automated analysis
critical priorityCVSS 4.0 base score is 9.4 (critical) with high EPSS and public exploit references, and successful exploitation yields arbitrary code execution on developer machines.
What it is
The @nestjs/devtools-integration package (versions 0.2.0 and below) exposes a local development HTTP server whose /inspector/graph/interact endpoint runs attacker-supplied code in a Node.js vm.runInNewContext sandbox. The sandbox is unsafe and cross-origin protections are missing, so a developer visiting a malicious website can have arbitrary code executed on their local machine. It is fixed in version 0.2.1.
Impact
An attacker gains arbitrary code execution on the developer's local machine, with high confidentiality, integrity and availability impact on both the vulnerable component and subsequent systems per the CVSS 4.0 vector.
Attack surface
Reached over an adjacent network (AV:A) via the locally running devtools HTTP server; no authentication (PR:N) and no user interaction (UI:N) are required per the vector, though the description notes a developer must have the package enabled and visit a malicious site.
Exploitation
Not listed in CISA KEV, but EPSS is 0.51324 (98.9th percentile) and multiple references are tagged Exploit, including a public PoC and vendor advisory, indicating public exploit material exists.
What to do
- Upgrade @nestjs/devtools-integration to version 0.2.1 or later.
- Disable or remove the devtools-integration package in any environment where it is not strictly needed.
- Do not run the devtools HTTP server on interfaces reachable beyond localhost, and restrict access to it.
- Add browser-side protections against cross-origin requests to localhost development servers where feasible.
Detection
- Monitor for requests to /inspector/graph/interact on local development servers, especially with JSON bodies containing a code field.
- Alert on Node.js processes spawning unexpected child processes or shells from development tooling.
- Review developer endpoints for cross-origin request patterns originating from external websites.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/JLLeitschuh/nestjs-devtools-integration-rce-poc | Exploit |
| https://github.com/JLLeitschuh/nestjs-typescript-starter-w-devtools-integration | Product |
| https://github.com/nestjs/nest/security/advisories/GHSA-85cg-cmq5-qjm7 | ExploitVendor Advisory |
| https://nodejs.org/api/vm.html | Product |
| https://socket.dev/blog/nestjs-rce-vuln | ExploitThird Party Advisory |
| https://github.com/nestjs/nest/security/advisories/GHSA-85cg-cmq5-qjm7 | ExploitVendor Advisory |
Track CVE-2025-54782 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-54782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.