๐Ÿ” CVE Alert

CVE-2026-104859

UNKNOWN 0.0

Nx: OS command injection in the @nx/docker release pipeline

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.

CWE CWE-78
Vendor nrwl
Product nx
Published Oct 2, 2026
Stay Ahead of the Next One

Get instant alerts for nrwl nx

Be the first to know when new unknown vulnerabilities affecting nrwl nx are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

nrwl / nx
>= 21.4.0, < 22.7.8 >= 23.0.0, < 23.1.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2 github.com: https://github.com/nrwl/nx/pull/36505 github.com: https://github.com/nrwl/nx/commit/6d60eed061f050e0d5af509a1f5a07c707f09865 github.com: https://github.com/nrwl/nx/commit/b587441fd8da28c5db37edb0826554e0060dc81b