GHSA-6vc5-vf29-ffr2: OS Command Injection
Summary
The @nx/docker release pipeline builds its docker invocations as shell command strings, interpolating release.docker.repositoryName and registryUrl from Nx configuration into them. Because those strings are handed to /bin/sh -c, a crafted repository or registry name executes as a command during nx release version and nx release publish. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.
Severity
Exploitable when someone runs a Docker release against attacker-supplied configuration, with high impact because release jobs hold publishing credentials. There is no known evidence of exploitation in the wild.
Affected & Patched Versions
| Package | Vulnerable | Patched | | --- | --- | --- | | @nx/docker | >= 21.4.0, < 22.7.8; >= 23.0.0, < 23.1.1 | 22.7.8, 23.1.1 |
Every published @nx/docker release before the patched versions is affected.
[!IMPORTANT] --dry-run does not protect you: one of the injected commands runs before the dry-run check, so even a dry-run publish reaches a shell.
Remediation
Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:
nx migrate 23.1.1
The fix is a drop-in and requires no configuration change. If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before your next publish, since the composed reference is read back from disk.
Details
Several docker commands in the release pipeline (docker tag during nx release version; the image existence check and docker push during nx release publish) are built as shell command strings with the image reference interpolated in. The reference is composed from the project's release.docker repositoryName and registryUrl, so a value containing shell syntax is executed rather than passed to docker.
Credits
- Arkadiusz Marta (RE:SOURCE) — Reporter
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
npm/@nx/dockerto a version that resolves this vulnerability.Fixed in 23.1.1 - Upgrade
Upgrade
npm/@nx/dockerto a version that resolves this vulnerability.Fixed in 22.7.8 - Upgrade
Upgrade
@nx/dockerto a version that resolves this vulnerability.Fixed in 22.7.8 - Upgrade
Upgrade
@nx/dockerto a version that resolves this vulnerability.Fixed in 23.1.1 - Operational
If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before the next publish.