Unprotected Unix Domain Sockets in Nx for TypeScript and Polyglot Codebases
CVE-2026-104854

8.5HIGH

Key Information:

Vendor

Nrwl

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104854?

Nx, a monorepo tool for TypeScript and other polyglot projects, has a vulnerability due to the creation of Unix domain sockets without proper directory and socket permissions in shared temporary locations. This security flaw allows unauthorized users, especially in a multi-user environment, to discover and connect to these sockets. The lack of authentication in socket transport poses risks as a malicious user can execute arbitrary code by controlling file paths processed by the Nx daemon. Furthermore, sensitive information related to the workspace can also be exposed through specific handlers. This issue has been addressed in the latest versions, 22.7.9 and 23.1.2.

Affected Version(s)

nx >= 14.6.0, < 22.7.9 < 14.6.0, 22.7.9

nx >= 23.0.0, < 23.1.2 < 23.0.0, 23.1.2

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.