Description
Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.
Published: 2026-10-02
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: Arbitrary File Write (potential RCE)
Action: Patch Now
AI Analysis

Impact

The vulnerability resides in the migration planning phase of Nx where the tool reads the nx-migrations.migrations field from a target package manifest. Because the field is not validated for containment, an attacker can supply a relative path that includes '..' segments or even an absolute path. During migration planning, the tool creates a temporary directory and later writes archive entries to that directory without checking whether the final path escapes the temporary directory. As a result, attacker-controlled bytes can be written outside the intended area, overwriting arbitrary files, truncating writable files even when no archive entry matches, or dropping malicious payloads. This flaw could be leveraged to inject or modify critical system or application files, potentially leading to privilege escalation or remote code execution depending on the privileges of the process running the migration.

Affected Systems

The flaw affects Nrwl Nx versions 13.10.0 through 22.7.9 (pre‑22.7.10) and all releases prior to 23.2.1. The issue was remedied in the 22.7.10 and 23.2.1 releases. Applications or monorepos that rely on any affected Nx version and invoke migration tooling—particularly when using the local migration flags or bypassing normal version resolution—are susceptible. Systems that automatically pull dependencies from untrusted registries or that provide direct malicious dependencies can expose the migration step to exploitation.

Risk and Exploitability

The CVSS base score of 5.8 indicates a moderate risk. The EPSS score is not available, but the vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to influence the nx migrate command, either by deploying a malicious package, manipulating the nx-migrations.migrations field, or configuring CI/CD pipelines to execute migration locally. Because the attack happens before review or execution of migrations, an unreviewed malicious path can affect the file system immediately. The potential for overwriting system files or inserting executable code makes the risk significant in shared or multi‑tenant environments, even though the baseline score is moderate.

Generated by OpenCVE AI on October 2, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to Nx 22.7.10 or later (23.2.1), ensuring the fix is applied.
  • If immediate upgrade is not possible, review all nx-migrations.migrations entries in your package manifests and ensure they contain only simple relative paths that do not include '..' or leading slashes before initiating any migration.
  • Disable or restrict the use of NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, and similar flags, and limit migration execution to trusted environments; audit your dependency tree for malicious packages that may supply unsafe migration data.

Generated by OpenCVE AI on October 2, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Nrwl
Nrwl nx
Vendors & Products Nrwl
Nrwl nx

Fri, 02 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
Description Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.
Title Nx: Path traversal in nx migrate package-migrations extraction
Weaknesses CWE-22
CWE-73
References
Metrics cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T17:41:54.417Z

Reserved: 2026-10-02T14:38:43.244Z

Link: CVE-2026-104853

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T17:17:03.920

Modified: 2026-10-02T18:17:01.837

Link: CVE-2026-104853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:30:18Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path