PT-2026-104406 · Nx · Nx
CVE-2026-104854
·
Published
2026-10-02
·
Updated
2026-10-02
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Nx versions prior to 22.7.9
Nx versions 23.0.0 through 23.1.1
Description
Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without restricting permissions to the owner. On shared build servers, developer hosts, or multi-user containers, an unprivileged local account can discover and connect to these sockets because the transport lacks authentication and relies solely on filesystem containment. A caller can send a
PROCESS IN BACKGROUND request containing a module path to invoke its default export, enabling remote code execution as the account running Nx. Additionally, other handlers may expose task hashes, project graphs, and workspace file contents.Recommendations
Update Nx to version 22.7.9.
Update Nx to version 23.1.2.
Fix
Improper Privilege Management
Incorrect Permission
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Nx