CVE-2026-104859High· 7.3▾ TwilightNx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 40.2 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-104854High· 8.5Nx is a monorepo solution for TypeScript and polyglot codebases
CVE-2026-104853Medium· 5.8Nx is a monorepo solution for TypeScript and polyglot codebases
CVE-2026-71476HighNx is a monorepo solution for TypeScript and polyglot codebases
CVE-2026-54753Medium· 5.9`nx graph` dev server permissive CORS policy
CVE-2025-14586Medium· 6.3A vulnerability was determined in TOTOLINK X5000R 9.1.0cu.2089_B20211224
CVE-2025-15472High· 7.2A flaw has been found in TRENDnet TEW-811DRU 1.0.2.0