Description
Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.
Published: 2026-10-02
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Local Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

Nx creates Unix domain sockets for its daemon and isolated plugin workers in temporary locations that are shared and lack owner‑only directory and socket permissions. Because the transport performs no authentication and relies solely on file system containment, an unprivileged local user on the same host can discover and connect to a running socket. The daemon’s PROCESS_IN_BACKGROUND request accepts a module path and executes its default export, allowing the caller to run arbitrary code as the account running Nx. Other handlers can expose workspace file contents, project graphs, and task hashes. This flaw is characterized by CWE‑269 (Privilege Escalation) and CWE‑732 (Incorrect Access Control).

Affected Systems

The affected product is Nx, a monorepo solution by nrwl. Versions from 14.6.0 through 22.7.8 and earlier 23.1.x releases are vulnerable. The issue was fixed in Nx releases 22.7.9 and 23.1.2. Single‑user systems that do not have additional local accounts are not exposed to this vulnerability.

Risk and Exploitability

The CVSS score of 8.5 indicates high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is local, requiring another user account on the same host to interact with the vulnerable sockets. An attacker with a local account can exploit the lack of authentication to execute code and read sensitive workspace data from the Nx process.

Generated by OpenCVE AI on October 2, 2026 at 18:22 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Nx to version 22.7.9 or later 23.1.2 to eliminate the vulnerable socket creation behavior.
  • If upgrading is not immediately possible, run Nx in an isolated environment with no other local users or configure the system temp directory to a private location that is only writable by the Nx user, ensuring that the directory and sockets have restrictive permissions (owner‑only).
  • Consider disabling the Nx daemon or plugin worker sockets when possible, and monitor the temporary directory for unexpected socket files or unauthorized connection attempts.

Generated by OpenCVE AI on October 2, 2026 at 18:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 18:45:00 +0000

Type Values Removed Values Added
First Time appeared Nrwl
Nrwl nx
Vendors & Products Nrwl
Nrwl nx

Fri, 02 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.
Title Nx daemon and plugin worker sockets are accessible to other local users
Weaknesses CWE-269
CWE-732
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T17:28:06.022Z

Reserved: 2026-10-02T14:38:43.244Z

Link: CVE-2026-104854

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T17:17:04.070

Modified: 2026-10-02T18:17:01.960

Link: CVE-2026-104854

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:30:18Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-732

    Incorrect Permission Assignment for Critical Resource