Impact
Nx creates Unix domain sockets for its daemon and isolated plugin workers in temporary locations that are shared and lack owner‑only directory and socket permissions. Because the transport performs no authentication and relies solely on file system containment, an unprivileged local user on the same host can discover and connect to a running socket. The daemon’s PROCESS_IN_BACKGROUND request accepts a module path and executes its default export, allowing the caller to run arbitrary code as the account running Nx. Other handlers can expose workspace file contents, project graphs, and task hashes. This flaw is characterized by CWE‑269 (Privilege Escalation) and CWE‑732 (Incorrect Access Control).
Affected Systems
The affected product is Nx, a monorepo solution by nrwl. Versions from 14.6.0 through 22.7.8 and earlier 23.1.x releases are vulnerable. The issue was fixed in Nx releases 22.7.9 and 23.1.2. Single‑user systems that do not have additional local accounts are not exposed to this vulnerability.
Risk and Exploitability
The CVSS score of 8.5 indicates high severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is local, requiring another user account on the same host to interact with the vulnerable sockets. An attacker with a local account can exploit the lack of authentication to execute code and read sensitive workspace data from the Nx process.
OpenCVE Enrichment