Cross-Origin Information Disclosure Vulnerability in Nx from Nrwl
CVE-2026-54753
5.9MEDIUM
What is CVE-2026-54753?
A cross-origin vulnerability in Nx allows developers to unknowingly expose sensitive server responses to any external website. When the local HTTP server initiated by Nx graph is active, it mistakenly sets the 'Access-Control-Allow-Origin' header to '*' in all responses. This misconfiguration potentially enables external sites to fetch information such as the full project graph and details from the /help endpoint, which could lead to unauthorized data exposure or even arbitrary command injection in rare situations. It is crucial for developers to upgrade to versions 22.7.2 or 23.0.0-beta.2 to remediate this flaw effectively.
Affected Version(s)
nx >= 17.0.4, < 22.7.2 < 17.0.4, 22.7.2
nx >= 23.0.0-beta.0, < 23.0.0-beta.2 < 23.0.0-beta.0, 23.0.0-beta.2
