File Extraction Vulnerability in Nx Monorepo Solution by Nrwl
CVE-2026-71476
8.7HIGH
What is CVE-2026-71476?
The Nx monorepo solution for TypeScript has a file extraction vulnerability that affects workspaces using self-hosted remote caches. Versions from 20.8.0 up to 22.7.7 and 23.0.2 allow a malicious remote cache server to deliver crafted tar archives, which can write files to unintended locations on the host machine. This flaw creates a pathway for potential remote code execution. It is important to note that Nx's default local cache and Nx Cloud are unaffected, and users should update to the fixed versions 22.7.7 or 23.0.2 to secure their environments.
Affected Version(s)
nx >= 20.8.0, < 22.7.7 < 20.8.0, 22.7.7
nx >= 23.0.0, < 23.0.2 < 23.0.0, 23.0.2
