PT-2026-104406 · Nx · Nx

CVE-2026-104854

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Nx versions prior to 22.7.9 Nx versions 23.0.0 through 23.1.1
Description Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without restricting permissions to the owner. On shared build servers, developer hosts, or multi-user containers, an unprivileged local account can discover and connect to these sockets because the transport lacks authentication and relies solely on filesystem containment. A caller can send a PROCESS IN BACKGROUND request containing a module path to invoke its default export, enabling remote code execution as the account running Nx. Additionally, other handlers may expose task hashes, project graphs, and workspace file contents.
Recommendations Update Nx to version 22.7.9. Update Nx to version 23.1.2.

Fix

Improper Privilege Management

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-104854

Affected Products

Nx