CVE-2026-104859

Source
https://cve.org/CVERecord?id=CVE-2026-104859
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104859.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104859
Aliases
  • GHSA-6vc5-vf29-ffr2
Published
2026-10-02T17:49:37Z
Modified
2026-10-04T02:46:03Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Nx: OS command injection in the @nx/docker release pipeline
Details

Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-78"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104859.json"
}
References

Affected packages

Git / github.com/nrwl/nx

Affected ranges

Type
GIT
Repo
https://github.com/nrwl/nx
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "21.4.0"
        },
        {
            "fixed":  "22.7.8"
        },
        {
            "introduced":  "23.0.0"
        },
        {
            "fixed":  "23.1.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

21.*
21.4.0
21.5.0-beta.0
21.5.0-beta.1
21.5.0-beta.2
21.5.1
21.5.1-beta.3
21.5.1-beta.4
21.5.1-beta.5
21.6.1
21.6.1-beta.0
21.6.1-beta.1
21.6.1-beta.2
21.6.1-beta.3
21.6.1-beta.4
21.6.1-rc.0
22.*
22.0.0
22.0.0-beta.0
22.0.0-beta.1
22.0.0-beta.2
22.0.0-beta.3
22.0.0-beta.4
22.0.0-beta.5
22.0.0-beta.6
22.0.0-beta.7
22.0.0-beta.8
22.0.0-beta.9
22.0.0-rc.0
22.0.1
22.1.0
22.1.0-beta.0
22.1.0-beta.1
22.1.0-beta.2
22.1.0-beta.3
22.1.0-beta.4
22.1.0-beta.5
22.1.0-beta.6
22.1.0-beta.7
22.1.0-beta.8
22.1.0-rc.0
22.1.0-rc.1
22.1.0-rc.2
22.1.0-rc.3
22.1.0-rc.4
22.1.0-rc.5
22.1.1
22.2.0
22.2.0-beta.0
22.2.0-beta.1
22.2.0-beta.2
22.2.0-beta.3
22.2.0-beta.4
22.2.1
22.2.2
22.2.3
22.3.0
22.3.0-beta.0
22.3.0-beta.1
22.3.0-beta.2
22.3.0-beta.3
22.4.0
22.4.0-beta.0
22.4.0-beta.1
22.4.0-beta.2
22.4.0-beta.3
22.4.0-beta.4
22.4.0-beta.5
22.4.1
22.5.0
22.5.0-beta.0
22.5.0-beta.1
22.5.0-beta.2
22.5.0-beta.3
22.5.0-beta.4
22.5.0-beta.5
22.6.0
22.6.0-beta.0
22.6.0-beta.1
22.6.0-beta.10
22.6.0-beta.11
22.6.0-beta.12
22.6.0-beta.13
22.6.0-beta.14
22.6.0-beta.2
22.6.0-beta.3
22.6.0-beta.4
22.6.0-beta.5
22.6.0-beta.6
22.6.0-beta.7
22.6.0-beta.8
22.6.0-beta.9
22.6.0-rc.0
22.6.0-rc.1
22.6.0-rc.2
22.7.0
22.7.0-beta.0
22.7.0-beta.1
22.7.0-beta.10
22.7.0-beta.11
22.7.0-beta.12
22.7.0-beta.13
22.7.0-beta.14
22.7.0-beta.15
22.7.0-beta.16
22.7.0-beta.17
22.7.0-beta.2
22.7.0-beta.3
22.7.0-beta.4
22.7.0-beta.5
22.7.0-beta.6
22.7.0-beta.7
22.7.0-beta.8
22.7.0-beta.9
22.7.0-rc.0
22.7.0-rc.1
22.7.0-rc.2
22.7.1
22.7.2
22.7.3
22.7.4
22.7.5
22.7.6
22.7.7
23.*
23.0.0
23.1.0
23.1.0-beta.0
23.1.0-beta.1
23.1.0-beta.2
23.1.0-beta.3
23.1.0-beta.4
23.1.0-beta.5
23.1.0-beta.6
23.1.0-beta.7
23.1.0-rc.0
23.1.0-rc.1
23.1.0-rc.2
23.1.0-rc.3
23.2.0-beta.0
23.2.0-beta.1
23.2.0-beta.2
23.2.0-beta.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104859.json"