CVE-2026-104854: Nx daemon and plugin worker sockets are accessible to other local users

Published Oct 2, 2026
·
Updated

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESSINBACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.

Affected Software

1 affected component
npm/nx>=14.6.0<22.7.9, >=23.0.0<23.1.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Nx to a version that resolves this vulnerability.

    Fixed in 22.7.9

Event History

Oct 2, 2026
CVE Published
via MITRE·04:59 PM
Data Sourced
via MITRE·04:59 PM
DescriptionWeakness

Frequently Asked Questions

1

Which environments are meaningfully exposed?

Exposure requires another unprivileged local account that can access shared temporary locations, such as on a shared build server, developer host, or multi-user container. Single-user machines without another local account are not exposed.

2

What does an attacker need to execute code through this issue?

An attacker needs local access as another unprivileged user, the ability to discover and connect to a running Nx socket, and control of a file path. The daemon's PROCESS_IN_BACKGROUND handler can invoke the default export of the supplied module as the account running Nx.

3

Does disabling the Nx daemon mitigate the issue?

No. Disabling the daemon does not remove the vulnerable sockets created for isolated plugin workers.

4

What information could a local attacker obtain without code execution?

Other socket handlers can expose workspace file contents, project graphs, and task hashes to a connected local user.

5

Which versions contain the fix?

The issue is fixed in Nx versions 22.7.9 and 23.1.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203