npm package intelligence

@nestjs/devtools-integration Known Exploited Vulnerabilities

Track evidence-backed exploitation affecting the npm package @nestjs/devtools-integration, including the gap beyond CISA KEV, confidence assessments, and sensor observations.

Total KEVs
1
Known exploited vulnerability affecting @nestjs/devtools-integration
In CISA KEV
0
Records also listed in the official catalog
Beyond CISA KEV
1
Additional exploited vulnerabilities absent from CISA KEV
Sensor Observed
0
@nestjs/devtools-integration KEVs with sensor-observed exploitation activity

Review @nestjs/devtools-integration exploitation against the versions you run

One of the one exploited @nestjs/devtools-integration vulnerabilities tracked here are not in CISA KEV.

0%
Covered by CISA
100%
Beyond CISA

Attested @nestjs/devtools-integration vulnerabilities

1 known exploited vulnerability affecting this package.

Vulnerability CISA KEV Added
CVE-2025-54782

@nestjs/devtools-integration's CSRF to Sandbox Escape Allows for RCE against JS Developers

Beyond CISA 18 Sep 2025

Recurring weakness patterns

Cross-Site Request Forgery (CSRF), Improper Neutralization of Special Elements used in a Command ('Command Injection'), and Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') account for mapped occurrences across this @nestjs/devtools-integration KEV portfolio.

Browse all KEVs →