nrwl has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was October 2026 with 3. The median CVSS is 7.3 (high).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
nrwl vulnerabilities
CVEs affecting nrwl, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-104859High· 7.3Nx is a monorepo solution for TypeScript and polyglot codebases
Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings…
CVE-2026-104854High· 8.5Nx is a monorepo solution for TypeScript and polyglot codebases
Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory an…
CVE-2026-104853Medium· 5.8Nx is a monorepo solution for TypeScript and polyglot codebases
Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contain…