File Extraction Vulnerability in Nx Monorepo Solution by Nrwl
CVE-2026-71476

8.7HIGH

Key Information:

Vendor

Nrwl

Status
Vendor
CVE Published:
6 August 2026

What is CVE-2026-71476?

The Nx monorepo solution for TypeScript has a file extraction vulnerability that affects workspaces using self-hosted remote caches. Versions from 20.8.0 up to 22.7.7 and 23.0.2 allow a malicious remote cache server to deliver crafted tar archives, which can write files to unintended locations on the host machine. This flaw creates a pathway for potential remote code execution. It is important to note that Nx's default local cache and Nx Cloud are unaffected, and users should update to the fixed versions 22.7.7 or 23.0.2 to secure their environments.

Affected Version(s)

nx >= 20.8.0, < 22.7.7 < 20.8.0, 22.7.7

nx >= 23.0.0, < 23.0.2 < 23.0.0, 23.0.2

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.