We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-54782

@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers



Description

Nest is a framework for building scalable Node.js server-side applications. In versions 0.2.0 and below, a critical Remote Code Execution (RCE) vulnerability was discovered in the @nestjs/devtools-integration package. When enabled, the package exposes a local development HTTP server with an API endpoint that uses an unsafe JavaScript sandbox (safe-eval-like implementation). Due to improper sandboxing and missing cross-origin protections, any malicious website visited by a developer can execute arbitrary code on their local machine. The package adds HTTP endpoints to a locally running NestJS development server. One of these endpoints, /inspector/graph/interact, accepts JSON input containing a code field and executes the provided code in a Node.js vm.runInNewContext sandbox. This is fixed in version 0.2.1.

Reserved 2025-07-29 | Published 2025-08-01 | Updated 2025-08-01 | Assigner GitHub_M


CRITICAL: 9.4CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Problem types

CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')

CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

CWE-352: Cross-Site Request Forgery (CSRF)

Product status

< 0.2.1
affected

References

github.com/...s/nest/security/advisories/GHSA-85cg-cmq5-qjm7

github.com/JLLeitschuh/nestjs-devtools-integration-rce-poc

github.com/...stjs-typescript-starter-w-devtools-integration

nodejs.org/api/vm.html

socket.dev/blog/nestjs-rce-vuln

cve.org (CVE-2025-54782)

nvd.nist.gov (CVE-2025-54782)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-54782

Support options

Helpdesk Chat, Email, Knowledgebase