GHSA-6vc5-vf29-ffr2

Suggest an improvement
Source
https://github.com/advisories/GHSA-6vc5-vf29-ffr2
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6vc5-vf29-ffr2/GHSA-6vc5-vf29-ffr2.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6vc5-vf29-ffr2
Aliases
Published
2026-10-05T23:29:13Z
Modified
2026-10-05T23:45:08Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
@nx/docker: OS command injection in the @nx/docker release pipeline
Details

Summary

The @nx/docker release pipeline builds its docker invocations as shell command strings, interpolating release.docker.repositoryName and registryUrl from Nx configuration into them. Because those strings are handed to /bin/sh -c, a crafted repository or registry name executes as a command during nx release version and nx release publish. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.

Severity

Exploitable when someone runs a Docker release against attacker-supplied configuration, with high impact because release jobs hold publishing credentials. There is no known evidence of exploitation in the wild.

Affected & Patched Versions

Package Vulnerable Patched
@nx/docker >= 21.4.0, < 22.7.8; >= 23.0.0, < 23.1.1 22.7.8, 23.1.1

Every published @nx/docker release before the patched versions is affected.

[!IMPORTANT] --dry-run does not protect you: one of the injected commands runs before the dry-run check, so even a dry-run publish reaches a shell.

Remediation

Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:

nx migrate 23.1.1

The fix is a drop-in and requires no configuration change. If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before your next publish, since the composed reference is read back from disk.

Details

Several docker commands in the release pipeline (docker tag during nx release version; the image existence check and docker push during nx release publish) are built as shell command strings with the image reference interpolated in. The reference is composed from the project's release.docker repositoryName and registryUrl, so a value containing shell syntax is executed rather than passed to docker.

Credits

  • Arkadiusz Marta (RE:SOURCE) — Reporter
Database specific
{
    "cwe_ids":  [
        "CWE-78"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-10-05T23:29:13Z",
    "nvd_published_at":  "2026-10-02T18:17:02Z",
    "severity":  "HIGH"
}
References

Affected packages

npm / @nx/docker

Package

Name
@nx/docker
View open source insights on deps.dev
Purl
pkg:npm/%40nx/docker

Affected ranges

Type
SEMVER
Events
Introduced
21.4.0
Fixed
22.7.8

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6vc5-vf29-ffr2/GHSA-6vc5-vf29-ffr2.json"

npm / @nx/docker

Package

Name
@nx/docker
View open source insights on deps.dev
Purl
pkg:npm/%40nx/docker

Affected ranges

Type
SEMVER
Events
Introduced
23.0.0
Fixed
23.1.1

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6vc5-vf29-ffr2/GHSA-6vc5-vf29-ffr2.json"