---
id: CVE-2026-104854
title: Nx is a monorepo solution for TypeScript and polyglot codebases
summary: >-
  Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0
  until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and
  isolated plugin workers in shared temporary locations without owner-only
  directory an…
severity: high
cvss: 8.5
cvssVector: 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'
cwe:
  - CWE-269
  - CWE-732
vendor: nrwl
product: nx
affected:
  - 'nx >= 14.6.0, < 22.7.9'
  - 'nx >= 23.0.0, < 23.1.2'
published: '2026-10-02'
updated: '2026-10-02'
sourceUpdated: '2026-10-02T18:17:01.960'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-104854'
references:
  - url: 'https://github.com/nrwl/nx/commit/3298fd8b2dd066167eb3cc0410643994a59b0bba'
    label: security-advisories@github.com
  - url: 'https://github.com/nrwl/nx/commit/63e1abb287a3d69f8ba981828a1de325d0d3dc68'
    label: security-advisories@github.com
  - url: 'https://github.com/nrwl/nx/commit/71c2253b6aac23b008e192c4e2642c42a5e07545'
    label: security-advisories@github.com
  - url: 'https://github.com/nrwl/nx/pull/36370'
    label: security-advisories@github.com
  - url: 'https://github.com/nrwl/nx/releases/tag/22.7.9'
    label: security-advisories@github.com
  - url: 'https://github.com/nrwl/nx/releases/tag/23.1.2'
    label: security-advisories@github.com
  - url: 'https://github.com/nrwl/nx/security/advisories/GHSA-w3vv-58gj-gw77'
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-02T17:27:34.092813Z'
cvssSource: cna
ingestedAt: '2026-10-02T17:24:03.906Z'
---

## Overview

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
