← Vulnerability feed

Vulnerability record · CVE-2025-54782 · published 2 August 2025

CVE-2025-54782: NestJS devtools-integration unsafe sandbox allows remote code execution

Nestjs · Devtools Integration

The @nestjs/devtools-integration package (versions 0.2.0 and below) exposes a local development HTTP server whose /inspector/graph/interact endpoint runs attacker-supplied code in a Node.js vm.runInNewContext sandbox. The sandbox is unsafe and cross-origin protections are missing, so a developer visiting a malicious website can have arbitrary code executed on their local machine. It is fixed in version 0.2.1.

9.4 CVSS 4.0 Critical EPSS 51% · top 1.1% CWE-77 · Command injectionCWE-78 · OS command injection
9.4CVSS 4.0 base score
51%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an unsafe JavaScript sandbox (safe-eval-like implementation). Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine. The package adds HTTP endpoints to a locally running NestJS development server. One of these endpoints, /inspector/graph/interact, accepts JSON input containing a code field and executes the provided code in a Node.js vm.runInNewContext sandbox. This is fixed in version 0.2.1.

CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

critical priorityCVSS 4.0 base score is 9.4 (critical) with high EPSS and public exploit references, and successful exploitation yields arbitrary code execution on developer machines.

What it is

The @nestjs/devtools-integration package (versions 0.2.0 and below) exposes a local development HTTP server whose /inspector/graph/interact endpoint runs attacker-supplied code in a Node.js vm.runInNewContext sandbox. The sandbox is unsafe and cross-origin protections are missing, so a developer visiting a malicious website can have arbitrary code executed on their local machine. It is fixed in version 0.2.1.

Impact

An attacker gains arbitrary code execution on the developer's local machine, with high confidentiality, integrity and availability impact on both the vulnerable component and subsequent systems per the CVSS 4.0 vector.

Attack surface

Reached over an adjacent network (AV:A) via the locally running devtools HTTP server; no authentication (PR:N) and no user interaction (UI:N) are required per the vector, though the description notes a developer must have the package enabled and visit a malicious site.

Exploitation

Not listed in CISA KEV, but EPSS is 0.51324 (98.9th percentile) and multiple references are tagged Exploit, including a public PoC and vendor advisory, indicating public exploit material exists.

What to do

  • Upgrade @nestjs/devtools-integration to version 0.2.1 or later.
  • Disable or remove the devtools-integration package in any environment where it is not strictly needed.
  • Do not run the devtools HTTP server on interfaces reachable beyond localhost, and restrict access to it.
  • Add browser-side protections against cross-origin requests to localhost development servers where feasible.

Detection

  • Monitor for requests to /inspector/graph/interact on local development servers, especially with JSON bodies containing a code field.
  • Alert on Node.js processes spawning unexpected child processes or shells from development tooling.
  • Review developer endpoints for cross-origin request patterns originating from external websites.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-54782 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-8037Progress LoadMaster API OS Command Injection RCEProgress LoadMaster (and related ADC products) contain an OS command injection flaw in multiple API command endpoints where unsanitized input is pass…KEVEPSS 77%analysed8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed7.2CVE-2025-29635D-Link DIR-823X command injection in set_prohibiting handlerD-Link DIR-823X firmware (240126 and 240802) contains a command injection flaw in the /goform/set_prohibiting POST handler. An attacker who already h…KEVEPSS 88%analysed8.1CVE-2026-22719VMware Aria Operations command injection during support-assisted migrationVMware Aria Operations contains a command injection flaw (CWE-77) that an unauthenticated attacker can use to run arbitrary commands, potentially ach…KEVEPSS 18%analysed8.7CVE-2025-4008Meteobridge web interface command injection without authenticationThe Meteobridge web interface, built from CGI shell scripts and C, exposes an endpoint vulnerable to command injection. Because the endpoint also lac…KEVEPSS 94%analysed6.1CVE-2025-59689Libraesva ESG command injection via compressed email attachmentLibraesva Email Security Gateway versions 4.5 through 5.5.x before 5.5.7 are vulnerable to command injection triggered by a compressed email attachme…KEVEPSS 1.9%analysed9.8CVE-2025-10035Fortra GoAnywhere MFT License Servlet deserialization to command injectionThe License Servlet in Fortra GoAnywhere MFT deserializes untrusted data, and an attacker who can present a validly forged license response signature…KEVEPSS 100%analysed8.8CVE-2020-25079D-Link DCS cameras authenticated command injection in ddns_enc.cgiD-Link DCS-2530L (before 1.06.01 Hotfix) and DCS-2670L (through 2.02) contain an authenticated command injection flaw in cgi-bin/ddns_enc.cgi. A user…KEVEPSS 54%analysed

Source: NIST National Vulnerability Database (record CVE-2025-54782), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.