Shell Command Injection in Nx by Nrwl
CVE-2026-104859
7.3HIGH
What is CVE-2026-104859?
Nx, a monorepo solution for TypeScript, is vulnerable to a shell command injection risk that arises when the release pipeline for Docker interacts with untrusted configuration values. This issue enables attackers to interpolate malicious shell commands into Docker build sequences, potentially allowing unauthorized execution within the context of the release job. Consequently, sensitive information such as registry credentials or cloud tokens could be exposed. Versions 22.7.8 and 23.1.1 contain fixes for this vulnerability.
Affected Version(s)
nx >= 21.4.0, < 22.7.8 < 21.4.0, 22.7.8
nx >= 23.0.0, < 23.1.1 < 23.0.0, 23.1.1
