Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104854— Nx daemon and plugin worker sockets are accessible to other local users

Quick assessment

Affected
nrwl nx
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nx 是用于 TypeScript 和多语言代码库的 monorepo 解决方案。在版本 14.6.0 至 22.7.9 以及 23.1.2 之前,Nx 在共享临时目录中为其守护进程和隔离的插件工作进程创建 Unix 域套接字,但未对目录和套接字设置仅所有者访问权限。在共享构建服务器、开发者主机或多用户容器中,其他非特权本地用户可以发现并连接到正在运行的套接字,因为该通信传输方式未进行身份验证,仅依赖文件系统隔离机制。 守护进程的 请求接受一个模块路径,并调用其默认导出函数,使得能够控制该文件的调用方可以以运行 N

CVSS 8.5 · High

Affected Version Matrix 2

VendorProduct Version RangeStatus
nrwl nx >= 14.6.0, < 22.7.9 affected
>= 23.0.0, < 23.1.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104854

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nx daemon and plugin worker sockets are accessible to other local users
Source: CVE Program / CVE List V5
Vulnerability Description
Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nrwl nx >= 14.6.0, < 22.7.9 -

II. Public POCs for CVE-2026-104854

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104854

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-104854 (1)

Vendor Pages for CVE-2026-104854 (2)

Same Patch Batch · nrwl · 2026-10-02 · 3 CVEs total

CVE-2026-104859 7.3 HIGH Nx: OS command injection in the @nx/docker release pipeline
CVE-2026-104853 5.8 MEDIUM Nx: Path traversal in nx migrate package-migrations extraction

IV. Related Vulnerabilities

V. Comments for CVE-2026-104854

No comments yet


Leave a comment