CVE-2026-71476High▾ TwilightNx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malici…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 41.3 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.6%
Last analysed / modified upstream
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious or on-path (MITM) remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on the machine running Nx, which can be escalated to remote code execution. Nx's default local cache and Nx Cloud are not affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed in versions 22.7.7 and 23.0.2.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
nx >= 20.8.0, < 22.7.7@nx/s3-cache <= 5.0.7@nx/gcs-cache <= 5.0.7@nx/azure-cache <= 5.0.7@nx/shared-fs-cache <= 5.0.7@nx/powerpack-s3-cache <= 5.0.7@nx/powerpack-gcs-cache <= 5.0.7@nx/powerpack-azure-cache <= 5.0.7@nx/powerpack-shared-fs-cache <= 5.0.7nx >= 23.0.0, < 23.0.2Patched in:
nx 22.7.7nx 23.0.2Connected by shared product, vendor, weakness, or advisory.
CVE-2022-30333High· 7.5RARLAB UnRAR before 6.12 on Linux and UNIX allows directory traversal to write to files during an extract (aka unpack) operation, as demonstrated by creating a ~/.ssh/authorized_keys file
CVE-2026-54753Medium· 5.9`nx graph` dev server permissive CORS policy
CVE-2026-19693High· 8.1extract-zip: extract-zip: Arbitrary file write via symlink in archive (CVE-2026-19693)
CVE-2026-15815High· 8.8Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives
CVE-2023-7260High· 7.5Path Traversal vulnerability discovered in OpenText™ CX-E Voice, affecting all version through 22.4
CVE-2023-7249Critical· 9.8Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in OpenText OpenText Directory Services allows Path Traversal.This issue affects OpenText Directory Services: from 16.4.2 before 24.1.