Cross-Origin Information Disclosure Vulnerability in Nx from Nrwl
CVE-2026-54753

5.9MEDIUM

Key Information:

Vendor

Nrwl

Status
Vendor
CVE Published:
26 June 2026

What is CVE-2026-54753?

A cross-origin vulnerability in Nx allows developers to unknowingly expose sensitive server responses to any external website. When the local HTTP server initiated by Nx graph is active, it mistakenly sets the 'Access-Control-Allow-Origin' header to '*' in all responses. This misconfiguration potentially enables external sites to fetch information such as the full project graph and details from the /help endpoint, which could lead to unauthorized data exposure or even arbitrary command injection in rare situations. It is crucial for developers to upgrade to versions 22.7.2 or 23.0.0-beta.2 to remediate this flaw effectively.

Affected Version(s)

nx >= 17.0.4, < 22.7.2 < 17.0.4, 22.7.2

nx >= 23.0.0-beta.0, < 23.0.0-beta.2 < 23.0.0-beta.0, 23.0.0-beta.2

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.