Shell Command Injection in Nx by Nrwl
CVE-2026-104859

7.3HIGH

Key Information:

Vendor

Nrwl

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-104859?

Nx, a monorepo solution for TypeScript, is vulnerable to a shell command injection risk that arises when the release pipeline for Docker interacts with untrusted configuration values. This issue enables attackers to interpolate malicious shell commands into Docker build sequences, potentially allowing unauthorized execution within the context of the release job. Consequently, sensitive information such as registry credentials or cloud tokens could be exposed. Versions 22.7.8 and 23.1.1 contain fixes for this vulnerability.

Affected Version(s)

nx >= 21.4.0, < 22.7.8 < 21.4.0, 22.7.8

nx >= 23.0.0, < 23.1.1 < 23.0.0, 23.1.1

References

CVSS V4

Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.