Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104853— Nx: Path traversal in nx migrate package-migrations extraction

Quick assessment

Affected
nrwl nx
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nx 是一个用于 TypeScript 和多语言代码库的 monorepo(单仓多包)解决方案。在版本 13.10.0 至 22.7.10 以及 23.2.1 之前,Nx 的迁移规划功能会从目标包的包清单(package manifest)中读取 字段,但未验证该值是否为受限的相对路径。恶意直接依赖项,或通过受信任包的 引入的包,可以在该字段中提供包含 路径段或绝对路径的值,导致 命令将本应逃逸到外部目录的路径拼接到其临时目录中。迁移存档随后可能将攻击者控制的字节写入临时目录之外的位置;此外,在打开目标输出流时,即

CVSS 5.8 · Medium

Affected Version Matrix 2

VendorProduct Version RangeStatus
nrwl nx >= 13.10.0, < 22.7.10 affected
>= 23.0.0, < 23.2.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104853

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nx: Path traversal in nx migrate package-migrations extraction
Source: CVE Program / CVE List V5
Vulnerability Description
Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对路径名的限制不恰当(路径遍历)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nrwl nx >= 13.10.0, < 22.7.10 -

II. Public POCs for CVE-2026-104853

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104853

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104853 (4)

Vendor Advisories for CVE-2026-104853 (1)

Vendor Pages for CVE-2026-104853 (1)

Same Patch Batch · nrwl · 2026-10-02 · 3 CVEs total

CVE-2026-104854 8.5 HIGH Nx daemon and plugin worker sockets are accessible to other local users
CVE-2026-104859 7.3 HIGH Nx: OS command injection in the @nx/docker release pipeline

IV. Related Vulnerabilities

V. Comments for CVE-2026-104853

No comments yet


Leave a comment