Description
Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.
Published: 2026-10-02
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: Remote Command Execution via Docker release pipeline
Action: Immediate Patch
AI Analysis

Impact

Nx, a monorepo solution, builds Docker commands in its release pipeline by concatenating the repositoryName and registryUrl configuration values into shell command strings that are executed by /bin/sh -c. This construction allows an attacker to inject arbitrary shell syntax into untrusted Nx configuration, leading to remote code execution. The attacker can run commands with the release job’s privileges and potentially expose registry credentials or cloud tokens. The weakness corresponds to CWE-78, an OS command injection flaw.

Affected Systems

The affected product is nrwl:nx, specifically versions from 21.4.0 up to 22.7.8 and from 23.0.0 up to 23.1.1. The vulnerability was fixed in the 22.7.8 release for the 21.4.0–22.7.8 series and in the 23.1.1 release for the 23.0.0–23.1.1 series.

Risk and Exploitability

The CVSS score of 7.3 classifies this issue as a high severity flaw. EPSS data is not available, but the lack of isolation and the ability for an attacker with repository modification rights to inject code means it remains a significant risk. The vulnerability is not listed in CISA’s KEV catalog. An attacker would typically need to alter repository configuration or submit a pull request that changes the release pipeline definition in order to exploit the flaw, and dry‑run publishing does not mitigate the risk.

Generated by OpenCVE AI on October 2, 2026 at 19:21 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Nx to version 22.7.8 or later (or 23.1.1 for the 23.* series) to apply the fix.
  • Restrict write access to Nx configuration files so that only trusted users can modify settings such as repositoryName and registryUrl.
  • Run the release pipeline in a constrained environment with the least privileges and avoid embedding credentials directly in the pipeline configuration.

Generated by OpenCVE AI on October 2, 2026 at 19:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Nrwl
Nrwl nx
Vendors & Products Nrwl
Nrwl nx

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Description Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.
Title Nx: OS command injection in the @nx/docker release pipeline
Weaknesses CWE-78
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-02T17:49:37.975Z

Reserved: 2026-10-02T14:38:43.244Z

Link: CVE-2026-104859

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-02T18:17:02.270

Modified: 2026-10-02T18:44:11.270

Link: CVE-2026-104859

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T19:30:17Z

Weaknesses
  • CWE-78

    Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')