Impact
Nx, a monorepo solution, builds Docker commands in its release pipeline by concatenating the repositoryName and registryUrl configuration values into shell command strings that are executed by /bin/sh -c. This construction allows an attacker to inject arbitrary shell syntax into untrusted Nx configuration, leading to remote code execution. The attacker can run commands with the release job’s privileges and potentially expose registry credentials or cloud tokens. The weakness corresponds to CWE-78, an OS command injection flaw.
Affected Systems
The affected product is nrwl:nx, specifically versions from 21.4.0 up to 22.7.8 and from 23.0.0 up to 23.1.1. The vulnerability was fixed in the 22.7.8 release for the 21.4.0–22.7.8 series and in the 23.1.1 release for the 23.0.0–23.1.1 series.
Risk and Exploitability
The CVSS score of 7.3 classifies this issue as a high severity flaw. EPSS data is not available, but the lack of isolation and the ability for an attacker with repository modification rights to inject code means it remains a significant risk. The vulnerability is not listed in CISA’s KEV catalog. An attacker would typically need to alter repository configuration or submit a pull request that changes the release pipeline definition in order to exploit the flaw, and dry‑run publishing does not mitigate the risk.
OpenCVE Enrichment