Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104859— Nx: OS command injection in the @nx/docker release pipeline

Quick assessment

Affected
nrwl nx
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Nx 是用于 TypeScript 和多语言代码库的 monorepo 解决方案。在版本 21.4.0 至 22.7.8,以及 23.0.0 至 23.1.1 期间,@nx/docker 的发布流水线(release pipeline)将 docker 标签构建、镜像查找和 docker push 操作作为 shell 命令字符串来执行。配置项 release.docker.repositoryName 和 registryUrl 会被插值(interpolated)到这些字符串中,并通过 /bin/sh -c 传

CVSS 7.3 · High

Affected Version Matrix 2

VendorProduct Version RangeStatus
nrwl nx >= 21.4.0, < 22.7.8 affected
>= 23.0.0, < 23.1.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104859

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Nx: OS command injection in the @nx/docker release pipeline
Source: CVE Program / CVE List V5
Vulnerability Description
Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
nrwl nx >= 21.4.0, < 22.7.8 -

II. Public POCs for CVE-2026-104859

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104859

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104859 (3)

Vendor Advisories for CVE-2026-104859 (1)

Same Patch Batch · nrwl · 2026-10-02 · 3 CVEs total

CVE-2026-104854 8.5 HIGH Nx daemon and plugin worker sockets are accessible to other local users
CVE-2026-104853 5.8 MEDIUM Nx: Path traversal in nx migrate package-migrations extraction

IV. Related Vulnerabilities

V. Comments for CVE-2026-104859

No comments yet


Leave a comment