PatchSiren

Prettier CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited Prettier CVE published 2026-01-22

CVE-2025-54313

CVE-2025-54313 is a CISA Known Exploited Vulnerabilities (KEV) entry affecting Prettier's eslint-config-prettier package. The supplied corpus describes it as an "Embedded Malicious Code Vulnerability" and indicates it was added to the KEV catalog on 2026-01-22 with a remediation due date of 2026-02-12. Because the provided source material is limited, the exact injection path, impacted versions, and exploi [truncated]