Unprotected Unix Domain Sockets in Nx for TypeScript and Polyglot Codebases
CVE-2026-104854
What is CVE-2026-104854?
Nx, a monorepo tool for TypeScript and other polyglot projects, has a vulnerability due to the creation of Unix domain sockets without proper directory and socket permissions in shared temporary locations. This security flaw allows unauthorized users, especially in a multi-user environment, to discover and connect to these sockets. The lack of authentication in socket transport poses risks as a malicious user can execute arbitrary code by controlling file paths processed by the Nx daemon. Furthermore, sensitive information related to the workspace can also be exposed through specific handlers. This issue has been addressed in the latest versions, 22.7.9 and 23.1.2.
Affected Version(s)
nx >= 14.6.0, < 22.7.9 < 14.6.0, 22.7.9
nx >= 23.0.0, < 23.1.2 < 23.0.0, 23.1.2
