CVE-2026-104853
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Nx Monorepo Tool

Vulnerability report for CVE-2026-104853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
nrwl nx From 13.10.0 (inc) to 22.7.10 (exc)
nrwl nx 22.7.10
nrwl nx 23.2.1
nrwl nx From 13.10.0 (inc) to 22.7.0 (exc)
nrwl nx From 23.0.0 (inc) to 23.2.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104853 is a path traversal vulnerability in Nx, a monorepo tool for TypeScript. It affects versions between 13.10.0 and 22.7.10 and 23.2.1. The issue occurs during migration planning when Nx reads the nx-migrations.migrations value from a package manifest without validating it. Attackers can supply paths with .. segments or absolute paths, causing files to be written outside the intended temporary directory. This can overwrite existing files even if no matching archive entry exists.

The vulnerability is triggered when users bypass the default nx@latest handoff using environment variables like NX_USE_LOCAL or flags such as --run-id. The fix validates migration paths to ensure they are relative and contained within the package directory.

Detection Guidance

Check Nx version with 'nx --version'. If using versions between 13.10.0 and 22.7.0 or 23.0.0 and 23.2.0, the system is vulnerable. Review package manifests for nx-migrations.migrations fields containing '..' or absolute paths.

Impact Analysis

This vulnerability allows attackers to write arbitrary files or truncate existing files outside the temporary directory used for migrations. This could include critical system files like shell configurations or git hooks, potentially leading to code execution. Attackers could exploit this by introducing a malicious package or manipulating a trusted package's dependencies.

Users who bypass the default nx@latest handoff or use vulnerable versions are at risk. The impact occurs during migration planning before users review or execute migrations, making it harder to detect.

Compliance Impact

This vulnerability could potentially violate compliance with standards like GDPR and HIPAA by allowing unauthorized file writes or truncations outside intended directories. Attackers could overwrite critical files such as configuration files, logs, or scripts, leading to data breaches, unauthorized access, or system compromise. Such actions may result in non-compliance with data protection and security requirements.

Mitigation Strategies

Upgrade Nx to version 22.7.10 or 23.2.1 or later. Avoid bypassing nx@latest handoff by removing NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, or NX_MIGRATE_CLI_VERSION overrides. Review and remove any suspicious package dependencies.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart