Impact
The vulnerability resides in the migration planning phase of Nx where the tool reads the nx-migrations.migrations field from a target package manifest. Because the field is not validated for containment, an attacker can supply a relative path that includes '..' segments or even an absolute path. During migration planning, the tool creates a temporary directory and later writes archive entries to that directory without checking whether the final path escapes the temporary directory. As a result, attacker-controlled bytes can be written outside the intended area, overwriting arbitrary files, truncating writable files even when no archive entry matches, or dropping malicious payloads. This flaw could be leveraged to inject or modify critical system or application files, potentially leading to privilege escalation or remote code execution depending on the privileges of the process running the migration.
Affected Systems
The flaw affects Nrwl Nx versions 13.10.0 through 22.7.9 (pre‑22.7.10) and all releases prior to 23.2.1. The issue was remedied in the 22.7.10 and 23.2.1 releases. Applications or monorepos that rely on any affected Nx version and invoke migration tooling—particularly when using the local migration flags or bypassing normal version resolution—are susceptible. Systems that automatically pull dependencies from untrusted registries or that provide direct malicious dependencies can expose the migration step to exploitation.
Risk and Exploitability
The CVSS base score of 5.8 indicates a moderate risk. The EPSS score is not available, but the vulnerability is not listed in CISA's KEV catalog. Exploitation requires the attacker to influence the nx migrate command, either by deploying a malicious package, manipulating the nx-migrations.migrations field, or configuring CI/CD pipelines to execute migration locally. Because the attack happens before review or execution of migrations, an unreviewed malicious path can affect the file system immediately. The potential for overwriting system files or inserting executable code makes the risk significant in shared or multi‑tenant environments, even though the baseline score is moderate.
OpenCVE Enrichment