GHSA-6vc5-vf29-ffr2: OS Command Injection

Published Oct 5, 2026
·
Updated

Summary

The @nx/docker release pipeline builds its docker invocations as shell command strings, interpolating release.docker.repositoryName and registryUrl from Nx configuration into them. Because those strings are handed to /bin/sh -c, a crafted repository or registry name executes as a command during nx release version and nx release publish. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.

Severity

Exploitable when someone runs a Docker release against attacker-supplied configuration, with high impact because release jobs hold publishing credentials. There is no known evidence of exploitation in the wild.

Affected & Patched Versions

| Package | Vulnerable | Patched | | --- | --- | --- | | @nx/docker | >= 21.4.0, < 22.7.8; >= 23.0.0, < 23.1.1 | 22.7.8, 23.1.1 |

Every published @nx/docker release before the patched versions is affected.

[!IMPORTANT] --dry-run does not protect you: one of the injected commands runs before the dry-run check, so even a dry-run publish reaches a shell.

Remediation

Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:

nx migrate 23.1.1

The fix is a drop-in and requires no configuration change. If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before your next publish, since the composed reference is read back from disk.

Details

Several docker commands in the release pipeline (docker tag during nx release version; the image existence check and docker push during nx release publish) are built as shell command strings with the image reference interpolated in. The reference is composed from the project's release.docker repositoryName and registryUrl, so a value containing shell syntax is executed rather than passed to docker.

Credits

- Arkadiusz Marta (RE:SOURCE) — Reporter

Affected Software

2 affected componentsFixes available
npm/@nx/docker>=23.0.0<23.1.1
23.1.1
npm/@nx/docker>=21.4.0<22.7.8
22.7.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/@nx/docker to a version that resolves this vulnerability.

    Fixed in 23.1.1
  2. Upgrade

    Upgrade npm/@nx/docker to a version that resolves this vulnerability.

    Fixed in 22.7.8
  3. Upgrade

    Upgrade @nx/docker to a version that resolves this vulnerability.

    Fixed in 22.7.8
  4. Upgrade

    Upgrade @nx/docker to a version that resolves this vulnerability.

    Fixed in 23.1.1
  5. Operational

    If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before the next publish.

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:29 PM
Data Sourced
via GitHub·11:29 PM
DescriptionWeaknessAffected Software

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203