CVE-2026-104854
Awaiting Analysis Awaiting Analysis - Queue

Unix Socket Authentication Bypass in Nx

Vulnerability report for CVE-2026-104854, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 7 associated CPEs
Vendor Product Version / Range
nrwl nx From 14.6.0 (inc) to 22.7.9 (inc)
nrwl nx 22.7.9
nrwl nx 23.1.2
nrwl nx From 14.6.0 (inc) to 22.7.9 (exc)
nrwl nx From 22.7.0 (inc) to 22.7.9 (exc)
nrwl nx From 23.0.0 (inc) to 23.1.2 (exc)
nrwl nx From 23.1.0 (inc) to 23.1.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
CWE-732 The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-104854 affects Nx versions between 14.6.0 and 22.7.8, and 23.0.0 to 23.1.1. It involves Unix domain sockets for the Nx daemon and plugin workers being created in shared temporary directories with default permissions. This allows other local users on multi-user systems to connect to these sockets, execute arbitrary code as the Nx user, and access sensitive data like workspace files or project graphs. The sockets lack authentication and rely solely on filesystem containment.

Detection Guidance

Check for Nx daemon or plugin worker sockets in system temp directories like /tmp or /var/tmp. Look for files named nx-daemon.sock or similar in /tmp/.nx/<uid>/sockets or ~/.nx/sockets. Verify socket permissions with 'ls -la /tmp/.nx/<uid>/sockets' or 'find /tmp -name '*nx*' -type s'. If sockets exist with permissions allowing group/other access, the system may be vulnerable.

Impact Analysis

If you use Nx on a shared build server, developer host, or multi-user container, another local user could exploit this to run malicious code as your user account, steal sensitive data, or disrupt builds. Single-user machines without additional local accounts are not affected. Disabling the daemon does not fully mitigate the issue as plugin-worker sockets remain vulnerable.

Mitigation Strategies

Upgrade Nx to version 22.7.9 or 23.1.2 or later. Run 'nx reset' to remove vulnerable sockets. Set NX_SOCKET_DIR to a restricted directory and disable the daemon as a temporary workaround. Ensure no shared users exist on the system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104854. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart