Repository navigation
fix(deps): update dependency nx to v23.2.1 [security] - autoclosed - #1187
Closed
renovate[bot] wants to merge 1 commit into
Closed
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
Contributor
|
Thank you for following the naming conventions! 🙏 |
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
renovate
Bot
force-pushed
the
renovate/npm-nx-vulnerability
branch
from
October 6, 2026 05:37
fe1fc50 to
c30070c
Compare
Signed-off-by: Renovate Bot <bot@renovateapp.com>
renovate
Bot
force-pushed
the
renovate/npm-nx-vulnerability
branch
from
October 6, 2026 12:09
c30070c to
3c3346c
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
23.1.1→23.2.1Nx: Path traversal in nx migrate package-migrations extraction
CVE-2026-104853 / GHSA-hrvq-x7jp-36xv
More information
Details
Summary
nx migratereads each target package'snx-migrations.migrationsvalue from its manifest and extracts the referenced file to a path built by joining that value onto a temporary directory. The value is never validated, so a package whosemigrationsfield contains..segments (or an absolute path) steers the extraction to write outside the temporary directory. A hostile package — or any package pulled in transitively through a trusted package'spackageGroup— can write attacker-controlled content, or truncate an existing file, anywhere the running user can write. This happens during migration planning, before the user reviews the migration list and before--run-migrations, so it does not require the user to approve or execute anything.Most workspaces need no action. By default
nx migratedoes not run the nx installed in your workspace — it installsnx@latestinto a temporary directory and performs the upgrade planning, including this extraction, with that copy. Now that a patched nx is the latest release, a defaultnx migraterun is unaffected whatever version the workspace has installed. The installed version only runs, and is only then exposed, when that hand-off is bypassed — see Remediation.Severity
Exploitable when the victim runs
nx migrateagainst a package the attacker controls, directly or through a trusted package'spackageGroup. The primary impact is a file write with attacker-controlled content and no path confinement; overwriting an auto-loaded file (a shell rc, a git hook, a CI script) escalates that write to code execution. There is no known evidence of exploitation in the wild.Affected & Patched Versions
nx>= 13.10.0, < 22.7.10;>= 23.0.0, < 23.2.122.7.10,23.2.1Every version in the ranges above is affected. The lower bound is 13.10.0, the first release where
nx migrateextracted a package's migrations file from its tarball; earlier versions resolved migrations without that extraction.Remediation
If you run
nx migratenormally, there is nothing to do. It resolves and runs the latest nx, which is patched, so your workspace's own nx version does not matter for this flaw.Upgrade only if you bypass that hand-off and run the workspace's nx instead — that is, if you set
NX_USE_LOCALorNX_MIGRATE_USE_LOCAL, pinNX_MIGRATE_CLI_VERSIONto an affected version, resume an existing run with--run-id, or run where the temporary install fails andnx migratefalls back to the local nx. In those cases upgrade to 22.7.10 (22.x line) or 23.2.1 (23.x line) or later:The fix is a drop-in — no configuration changes are required, and no legitimate
migrationsvalue is affected (real packages reference./migrations.jsonor another path within their own directory, all of which remain valid). Either way, do not runnx migrateagainst packages, orpackageGroupmembers, that you do not trust.Details
While planning an upgrade,
nx migrateextracts each target package's migrations file to a destination built by joining the package's ownnx-migrations.migrationsvalue onto a temporary directory. That value is read from the manifest without validation, and it is handled asymmetrically: the name Nx matches against the archive entries is normalized (so its..segments collapse), while the destination path it writes to is a raw join that keeps the..segments and resolves outside the temporary directory. Because the attacker controls the tarball, they name their entry to equal the normalized form; the match then succeeds and the bytes are written to the un-normalized, escaping destination. The normalization is not a defence — it only dictates what the attacker must name their entry.The same value also seeds the directory used for prompt-file extraction, which has the same shape, so both writes are steerable from the one field.
Two distinct primitives fall out of this:
migrationsat an existing file empties that file even when no tar entry matches — no crafted archive required.Credits
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Nx daemon and plugin worker sockets are accessible to other local users
CVE-2026-104854 / GHSA-w3vv-58gj-gw77
More information
Details
Summary
Nx creates the Unix domain sockets for its daemon and its plugin workers in a shared temporary directory with default permissions, so any other user on the same machine can connect to them. The daemon accepts a
PROCESS_IN_BACKGROUNDrequest that names a module to load and invokes its default export, which turns socket access into code execution inside the daemon process. On a multi-user machine — a shared build server, a shared developer box, or a container running several accounts — one local user can execute code as another user running Nx.Severity
Exploitable by any other unprivileged local user on a shared host while a daemon or plugin worker is running, with no user interaction. There is no known evidence of exploitation in the wild.
Affected & Patched Versions
nx>= 14.6.0, < 22.7.9;>= 23.0.0, < 23.1.222.7.9,23.1.2Every version in the ranges above is affected. The lower bound is 14.6.0, when the daemon request handler that turns socket access into code execution was added.
Remediation
Upgrade to 22.7.9 (22.x line) or 23.1.2 (23.x line) or later:
On a shared machine, run
nx resetafter upgrading so that any sockets and directories created by an older version are removed rather than reused.If you cannot upgrade, point
NX_SOCKET_DIRat a directory you own with mode0700, which is already honoured by the vulnerable versions, and disable the daemon withNX_DAEMON=falseto reduce the reachable surface — though, per the callout above, that does not remove the plugin worker sockets.Details
The daemon and the plugin workers communicate over Unix domain sockets placed in a subdirectory of the shared OS temporary directory. That directory is created with default permissions, which on a typical system leave it readable and traversable by every user on the machine, and nothing narrows the socket files themselves. The directory name is derived from a hash of the workspace path and the process id, so it is unique but not secret — any local user who lists the temporary directory can find it.
The connection carries no authentication: the containment is meant to be the filesystem permissions alone, and those are too broad. Any local process that can reach the socket is treated as a fully trusted client.
The impact of that access is set by what the daemon's request handlers allow. One handler takes a module path from the request and loads and invokes it; because an absolute path resolves regardless of the lookup constraints in place, a caller who can write a file anywhere on the machine — their own home directory suffices — and connect to the socket can have the daemon execute it, as the user running the daemon. Other handlers expose workspace file contents, the project graph, and task hashes to the same unauthenticated caller.
Credits
Reported by researchers at the University of Sydney:
Severity
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nrwl/nx (nx)
v23.2.1Compare Source
23.2.1 (2026-09-09)
🚀 Features
🩹 Fixes
❤️ Thank You
v23.2.0Compare Source
23.2.0 (2026-09-02)
🚀 Features
🩹 Fixes
ng-packagrlazily (#36632)nx affected(#36569, #36568)@find(#36526)❤️ Thank You
v23.1.3Compare Source
23.1.3 (2026-08-31)
🩹 Fixes
ng-packagrlazily (#36632)❤️ Thank You
v23.1.2Compare Source
23.1.2 (2026-08-26)
🩹 Fixes
nx affected(#36569, #36568)Configuration
📅 Schedule: (in timezone Europe/Berlin)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.