Search

Find a vulnerability

Search criteria

    5 vulnerabilities found for nx by nrwl

    CVE-2026-104859 (GCVE-0-2026-104859)

    Vulnerability from cvelistv5 – Published: 2026-10-02 17:49 – Updated: 2026-10-02 17:49
    VLAI
    Title
    Nx: OS command injection in the @nx/docker release pipeline
    Summary
    Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.
    CWE
    • CWE-78 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
    Impacted products
    Vendor Product Version
    nrwl nx Affected: >= 21.4.0, < 22.7.8
    Affected: >= 23.0.0, < 23.1.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "product": "nx",
              "vendor": "nrwl",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 21.4.0, \u003c 22.7.8"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 23.0.0, \u003c 23.1.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job\u0027s privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 7.3,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-78",
                  "description": "CWE-78: Improper Neutralization of Special Elements used in an OS Command (\u0027OS Command Injection\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T17:49:37.975Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2"
            },
            {
              "name": "https://github.com/nrwl/nx/pull/36505",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/pull/36505"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/6d60eed061f050e0d5af509a1f5a07c707f09865",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/6d60eed061f050e0d5af509a1f5a07c707f09865"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/b587441fd8da28c5db37edb0826554e0060dc81b",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/b587441fd8da28c5db37edb0826554e0060dc81b"
            }
          ],
          "source": {
            "advisory": "GHSA-6vc5-vf29-ffr2",
            "discovery": "UNKNOWN"
          },
          "title": "Nx: OS command injection in the @nx/docker release pipeline"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104859",
        "datePublished": "2026-10-02T17:49:37.975Z",
        "dateReserved": "2026-10-02T14:38:43.244Z",
        "dateUpdated": "2026-10-02T17:49:37.975Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104854 (GCVE-0-2026-104854)

    Vulnerability from cvelistv5 – Published: 2026-10-02 16:59 – Updated: 2026-10-02 17:28
    VLAI
    Title
    Nx daemon and plugin worker sockets are accessible to other local users
    Summary
    Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 17:27 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    • CWE-732 - Incorrect Permission Assignment for Critical Resource
    Impacted products
    Vendor Product Version
    nrwl nx Affected: >= 14.6.0, < 22.7.9
    Affected: >= 23.0.0, < 23.1.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104854",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T17:27:34.092813Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T17:28:06.022Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "nx",
              "vendor": "nrwl",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 14.6.0, \u003c 22.7.9"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 23.0.0, \u003c 23.1.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon\u0027s PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "LOCAL",
                "baseScore": 8.5,
                "baseSeverity": "HIGH",
                "privilegesRequired": "LOW",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "NONE",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269: Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-732",
                  "description": "CWE-732: Incorrect Permission Assignment for Critical Resource",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T16:59:48.238Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/nrwl/nx/security/advisories/GHSA-w3vv-58gj-gw77",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/nrwl/nx/security/advisories/GHSA-w3vv-58gj-gw77"
            },
            {
              "name": "https://github.com/nrwl/nx/pull/36370",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/pull/36370"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/3298fd8b2dd066167eb3cc0410643994a59b0bba",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/3298fd8b2dd066167eb3cc0410643994a59b0bba"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/63e1abb287a3d69f8ba981828a1de325d0d3dc68",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/63e1abb287a3d69f8ba981828a1de325d0d3dc68"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/71c2253b6aac23b008e192c4e2642c42a5e07545",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/71c2253b6aac23b008e192c4e2642c42a5e07545"
            },
            {
              "name": "https://github.com/nrwl/nx/releases/tag/22.7.9",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/releases/tag/22.7.9"
            },
            {
              "name": "https://github.com/nrwl/nx/releases/tag/23.1.2",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/releases/tag/23.1.2"
            }
          ],
          "source": {
            "advisory": "GHSA-w3vv-58gj-gw77",
            "discovery": "UNKNOWN"
          },
          "title": "Nx daemon and plugin worker sockets are accessible to other local users"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104854",
        "datePublished": "2026-10-02T16:59:48.238Z",
        "dateReserved": "2026-10-02T14:38:43.244Z",
        "dateUpdated": "2026-10-02T17:28:06.022Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-104853 (GCVE-0-2026-104853)

    Vulnerability from cvelistv5 – Published: 2026-10-02 16:52 – Updated: 2026-10-02 17:41
    VLAI
    Title
    Nx: Path traversal in nx migrate package-migrations extraction
    Summary
    Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-02 17:41 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-73 - External Control of File Name or Path
    Impacted products
    Vendor Product Version
    nrwl nx Affected: >= 13.10.0, < 22.7.10
    Affected: >= 23.0.0, < 23.2.1
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-104853",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-02T17:41:40.332975Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-02T17:41:54.417Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "nx",
              "vendor": "nrwl",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 13.10.0, \u003c 22.7.10"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 23.0.0, \u003c 23.2.1"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package\u0027s packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "PRESENT",
                "attackVector": "LOCAL",
                "baseScore": 5.8,
                "baseSeverity": "MEDIUM",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "LOW",
                "vulnConfidentialityImpact": "LOW",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73: External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T16:52:07.624Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/nrwl/nx/security/advisories/GHSA-hrvq-x7jp-36xv",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/nrwl/nx/security/advisories/GHSA-hrvq-x7jp-36xv"
            },
            {
              "name": "https://github.com/nrwl/nx/pull/36887",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/pull/36887"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/38cd82a0c05e8212e538bdb87ccb198d6504e58f",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/38cd82a0c05e8212e538bdb87ccb198d6504e58f"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/95474ab457e8e1dbdbefad29040c166105a8fb90",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/95474ab457e8e1dbdbefad29040c166105a8fb90"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/de37c5ebd1852fac700d70726326236ac398af3f",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/de37c5ebd1852fac700d70726326236ac398af3f"
            },
            {
              "name": "https://github.com/nrwl/nx/releases/tag/22.7.10",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/releases/tag/22.7.10"
            },
            {
              "name": "https://github.com/nrwl/nx/releases/tag/23.2.1",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/releases/tag/23.2.1"
            }
          ],
          "source": {
            "advisory": "GHSA-hrvq-x7jp-36xv",
            "discovery": "UNKNOWN"
          },
          "title": "Nx: Path traversal in nx migrate package-migrations extraction"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-104853",
        "datePublished": "2026-10-02T16:52:07.624Z",
        "dateReserved": "2026-10-02T14:38:43.244Z",
        "dateUpdated": "2026-10-02T17:41:54.417Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-71476 (GCVE-0-2026-71476)

    Vulnerability from cvelistv5 – Published: 2026-08-06 20:07 – Updated: 2026-08-08 02:33
    VLAI
    Title
    Nx: Zip-Slip in the self-hosted remote cache
    Summary
    Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious or on-path (MITM) remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx, which can be escalated to remote code execution. Nx's default local cache and Nx Cloud are not affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed in versions 22.7.7 and 23.0.2.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-08-08 02:32 UTC
    CWE
    • CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
    • CWE-59 - Improper Link Resolution Before File Access ('Link Following')
    Impacted products
    Vendor Product Version
    nrwl nx Affected: >= 20.8.0, < 22.7.7
    Affected: >= 23.0.0, < 23.0.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-71476",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-08-08T02:32:54.880409Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-08-08T02:33:11.207Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "nx",
              "vendor": "nrwl",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 20.8.0, \u003c 22.7.7"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 23.0.0, \u003c 23.0.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious or on-path (MITM) remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx, which can be escalated to remote code execution. Nx\u0027s default local cache and Nx Cloud are not affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed in versions 22.7.7 and 23.0.2."
            }
          ],
          "metrics": [
            {
              "cvssV4_0": {
                "attackComplexity": "LOW",
                "attackRequirements": "NONE",
                "attackVector": "NETWORK",
                "baseScore": 8.7,
                "baseSeverity": "HIGH",
                "privilegesRequired": "NONE",
                "subAvailabilityImpact": "NONE",
                "subConfidentialityImpact": "NONE",
                "subIntegrityImpact": "NONE",
                "userInteraction": "PASSIVE",
                "vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N",
                "version": "4.0",
                "vulnAvailabilityImpact": "HIGH",
                "vulnConfidentialityImpact": "HIGH",
                "vulnIntegrityImpact": "HIGH"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-22",
                  "description": "CWE-22: Improper Limitation of a Pathname to a Restricted Directory (\u0027Path Traversal\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-59",
                  "description": "CWE-59: Improper Link Resolution Before File Access (\u0027Link Following\u0027)",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-08-06T20:07:09.019Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/nrwl/nx/security/advisories/GHSA-vp3h-ghgh-jr7g",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/nrwl/nx/security/advisories/GHSA-vp3h-ghgh-jr7g"
            },
            {
              "name": "https://github.com/nrwl/nx/pull/36116",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/pull/36116"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/2b20c2da39d263c32ae05767577589481a309fee",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/2b20c2da39d263c32ae05767577589481a309fee"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/a82807621e4176e37909d2c1afede661b45cc30",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/a82807621e4176e37909d2c1afede661b45cc30"
            },
            {
              "name": "https://github.com/nrwl/nx/commit/ad296578fe980a4aad66f8af0add21f6ddf907d9",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/commit/ad296578fe980a4aad66f8af0add21f6ddf907d9"
            }
          ],
          "source": {
            "advisory": "GHSA-vp3h-ghgh-jr7g",
            "discovery": "UNKNOWN"
          },
          "title": "Nx: Zip-Slip in the self-hosted remote cache"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-71476",
        "datePublished": "2026-08-06T20:07:09.019Z",
        "dateReserved": "2026-08-06T19:56:23.724Z",
        "dateUpdated": "2026-08-08T02:33:11.207Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-54753 (GCVE-0-2026-54753)

    Vulnerability from cvelistv5 – Published: 2026-06-26 18:13 – Updated: 2026-06-26 19:09
    VLAI
    Title
    Nx: `nx graph` dev server permissive CORS policy
    Summary
    Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Origin: * on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the /help endpoint, which runs a target's configured help command. The practical impact is typically cross-origin information disclosure, but can be arbitrary command injection in rare cases. This vulnerability is fixed in 22.7.2 and 23.0.0-beta.2.
    SSVC
    Exploitation: none Automatable: no Technical Impact: partial
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-06-26 19:09 UTC
    CWE
    • CWE-749 - Exposed Dangerous Method or Function
    • CWE-942 - Permissive Cross-domain Policy with Untrusted Domains
    References
    Impacted products
    Vendor Product Version
    nrwl nx Affected: >= 17.0.4, < 22.7.2
    Affected: >= 23.0.0-beta.0, < 23.0.0-beta.2
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-54753",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "no"
                      },
                      {
                        "Technical Impact": "partial"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-06-26T19:09:19.972525Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-06-26T19:09:33.257Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "product": "nx",
              "vendor": "nrwl",
              "versions": [
                {
                  "status": "affected",
                  "version": "\u003e= 17.0.4, \u003c 22.7.2"
                },
                {
                  "status": "affected",
                  "version": "\u003e= 23.0.0-beta.0, \u003c 23.0.0-beta.2"
                }
              ]
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Origin: * on every response, letting any website a developer visited read the server\u0027s responses cross-origin \u2014 including the full project graph and the output of the /help endpoint, which runs a target\u0027s configured help command. The practical impact is typically cross-origin information disclosure, but can be arbitrary command injection in rare cases. This vulnerability is fixed in 22.7.2 and 23.0.0-beta.2."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "attackComplexity": "HIGH",
                "attackVector": "NETWORK",
                "availabilityImpact": "NONE",
                "baseScore": 5.9,
                "baseSeverity": "MEDIUM",
                "confidentialityImpact": "HIGH",
                "integrityImpact": "LOW",
                "privilegesRequired": "NONE",
                "scope": "UNCHANGED",
                "userInteraction": "REQUIRED",
                "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:L/A:N",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-749",
                  "description": "CWE-749: Exposed Dangerous Method or Function",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            },
            {
              "descriptions": [
                {
                  "cweId": "CWE-942",
                  "description": "CWE-942: Permissive Cross-domain Policy with Untrusted Domains",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-06-26T18:13:34.371Z",
            "orgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
            "shortName": "GitHub_M"
          },
          "references": [
            {
              "name": "https://github.com/nrwl/nx/security/advisories/GHSA-g2r8-wvmj-jf5w",
              "tags": [
                "x_refsource_CONFIRM"
              ],
              "url": "https://github.com/nrwl/nx/security/advisories/GHSA-g2r8-wvmj-jf5w"
            },
            {
              "name": "https://github.com/nrwl/nx/pull/35494",
              "tags": [
                "x_refsource_MISC"
              ],
              "url": "https://github.com/nrwl/nx/pull/35494"
            }
          ],
          "source": {
            "advisory": "GHSA-g2r8-wvmj-jf5w",
            "discovery": "UNKNOWN"
          },
          "title": "Nx: `nx graph` dev server permissive CORS policy"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "a0819718-46f1-4df5-94e2-005712e83aaa",
        "assignerShortName": "GitHub_M",
        "cveId": "CVE-2026-54753",
        "datePublished": "2026-06-26T18:13:34.371Z",
        "dateReserved": "2026-06-15T23:12:41.965Z",
        "dateUpdated": "2026-06-26T19:09:33.257Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }