CVE-2026-104859
Awaiting Analysis Awaiting Analysis - Queue

Command Injection in Nx Monorepo Tool

Vulnerability report for CVE-2026-104859, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: GitHub, Inc.

Description

Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 6 associated CPEs
Vendor Product Version / Range
nx docker From 21.4.0 (inc) to 22.7.8 (inc)
nx docker From 23.0.0 (inc) to 23.1.1 (inc)
nrwl nx to 22.7.8 (exc)
nrwl nx 22.7.8
nrwl nx to 23.1.1 (exc)
nrwl nx 23.1.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-78 The product constructs all or part of an OS command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended OS command when it is sent to a downstream component.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an OS command injection flaw in the Nx Docker release pipeline. It affects versions of @nx/docker from 21.4.0 to 22.7.7 and 23.0.0 to 23.1.0. The issue occurs because Docker commands like docker tag, docker push, and docker images are constructed as shell command strings with interpolated configuration values. If these values contain shell syntax, they can execute arbitrary commands when passed to /bin/sh -c during nx release version or nx release publish operations.

Detection Guidance

Check if your Nx Docker plugin version is within the vulnerable range (21.4.0 to 22.7.7 or 23.0.0 to 23.1.0). Run 'npm list @nx/docker' to verify the installed version. If vulnerable, inspect CI/CD logs for nx release version or nx release publish commands for unexpected shell syntax execution.

Impact Analysis

An attacker could inject commands via untrusted Nx configuration, such as a pull request modifying repository settings. These commands would execute with the privileges of the release job, potentially exposing registry credentials, cloud tokens, or other sensitive data. Even dry-run publishing does not prevent the vulnerable pre-check command from executing.

Compliance Impact

This vulnerability could lead to unauthorized command execution, potentially resulting in data breaches or unauthorized access to sensitive information. Such incidents may violate compliance requirements under GDPR, HIPAA, or other regulations that mandate protection of personal or health data and secure handling of credentials and tokens.

Mitigation Strategies

Upgrade @nx/docker to version 22.7.8 or later, or 23.1.1 or later. If you used a vulnerable version with untrusted configuration, delete the generated Docker version file before the next publish to prevent re-execution of injected commands.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104859. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart