Nx 是一个用于 TypeScript 和多语言代码库的 monorepo(单仓多包)解决方案。在版本 13.10.0 至 22.7.10 以及 23.2.1 之前,Nx 的迁移规划功能会从目标包的包清单(package manifest)中读取 字段,但未验证该值是否为受限的相对路径。恶意直接依赖项,或通过受信任包的 引入的包,可以在该字段中提供包含 路径段或绝对路径的值,导致 命令将本应逃逸到外部目录的路径拼接到其临时目录中。迁移存档随后可能将攻击者控制的字节写入临时目录之外的位置;此外,在打开目标输出流时,即
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-104854 | 8.5 HIGH | Nx daemon and plugin worker sockets are accessible to other local users |
| CVE-2026-104859 | 7.3 HIGH | Nx: OS command injection in the @nx/docker release pipeline |
No comments yet