Path Traversal Vulnerability in Nx by Nrwl Affecting Migration Planning
CVE-2026-104853

5.8MEDIUM

Key Information:

Vendor

Nrwl

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104853?

A path traversal vulnerability exists in the Nx migration planning feature, allowing potential attackers to manipulate file paths via the nx-migrations.migrations value from a target package manifest. This flaw could lead to unauthorized file access or modification, as it permits malicious packages to exploit the absence of validation on path inputs. Consequently, when migration planning occurs, there is a risk that an attacker can write data outside the intended temporary directory. This issue is remedied in Nx versions 22.7.10 and 23.2.1.

Affected Version(s)

nx >= 13.10.0, < 22.7.10 < 13.10.0, 22.7.10

nx >= 23.0.0, < 23.2.1 < 23.0.0, 23.2.1

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.