GHSA-w2vw-w76x-qr89: OS Command Injection

Published Oct 5, 2026
·
Updated

Summary

Nx core builds several git invocations as shell command strings with untrusted values interpolated into them, so a value that should be a git revision or ref is parsed by /bin/sh instead. Two entry points are reachable by an attacker: affected commands, where defaultBase / affected.defaultBase from nx.json (and the NXBASE / NXHEAD environment variables) reach git merge-base and git diff; and nx import, where a branch name advertised by a remote repository reaches git fetch, git checkout, and git config. In both cases an attacker who controls a repository — or who opens a pull request against one — gets arbitrary command execution on the machine of anyone who runs an ordinary Nx command against it, including CI runners.

The affected path is the more serious of the two. nx affected and nx show projects --affected run constantly in CI, so a pull request that changes nothing but nx.json is enough to execute code on the runner with whatever credentials that job holds.

Severity

Exploitable by anyone who controls repository content — a fork's pull request, or a repository the victim clones — that the victim then runs an ordinary nx affected or nx import against; no access to the victim's machine is required. We have no evidence of exploitation in the wild.

Affected & Patched Versions

| Package | Vulnerable | Patched | | --- | --- | --- | | nx | >= 14.0.0, < 22.7.8; >= 23.0.0, < 23.1.1 | 22.7.8, 23.1.1 |

Treat every version below the patched ones as affected.

Remediation

Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:

nx migrate 23.1.1

The fix is a drop-in — no configuration changes are required. If you cannot upgrade, treat nx.json from untrusted sources as executable content, do not run affected commands against pull requests you have not reviewed, and do not run nx import against repositories you do not trust.

Details

affected commands

Nx computes the merge base and the changed-file set by building git merge-base and git diff command lines as strings and running them through a shell. The base and head revisions in those strings come from nx.json's defaultBase / affected.defaultBase or from the NXBASE / NXHEAD environment variables, and a related code path reads file contents with git show <revision>:<path> the same way. Because a shell parses the whole line, a revision value containing shell syntax is executed rather than passed to git.

The revisions are wrapped in double quotes, which looks protective but is not: POSIX shells still perform command substitution inside double quotes, so a value of $(…) runs without needing to break out of the quotes.

nx import

The GitRepository helper runs every git operation — fetch, checkout, reset, config, and others — by interpolating its arguments into a shell command string. The untrusted argument is a branch name: nx import lists the branches a remote advertises, offers them to the user to choose from, and feeds the chosen name back into those commands. A hostile repository controls the names of its own branches, so it controls the command that runs when one is selected.

Credits

- Arkadiusz Marta (RE:SOURCE) — Reporter

Affected Software

2 affected componentsFixes available
npm/nx>=23.0.0<23.1.1
23.1.1
npm/nx>=14.0.0<22.7.8
22.7.8

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade npm/nx to a version that resolves this vulnerability.

    Fixed in 23.1.1
  2. Upgrade

    Upgrade npm/nx to a version that resolves this vulnerability.

    Fixed in 22.7.8
  3. Upgrade

    Upgrade nx to a version that resolves this vulnerability.

    Fixed in 22.7.8
  4. Upgrade

    Upgrade nx to a version that resolves this vulnerability.

    Fixed in 23.1.1

Event History

Oct 5, 2026
Advisory Published
via GitHub·11:29 PM
Data Sourced
via GitHub·11:29 PM
DescriptionWeaknessAffected Software

Frequently Asked Questions

1

Who is most exposed to this issue?

CI runners and developer machines that run Nx commands against repositories containing attacker-controlled content are exposed. This includes repositories cloned from an untrusted source and CI jobs that run on pull requests from forks.

2

Which Nx workflows can trigger command execution?

The affected-command path can be reached through nx affected and nx show projects --affected. The import path can be reached through nx import when it processes a branch name advertised by a remote repository.

3

What attacker-controlled inputs reach the shell?

For affected commands, defaultBase or affected.defaultBase in nx.json, plus the NX_BASE and NX_HEAD environment variables, can reach git merge-base and git diff. For nx import, a remote-advertised branch name can reach git fetch, git checkout, and git config.

4

Can a pull request trigger the issue without changing application code?

Yes. A pull request that only changes nx.json can be sufficient to execute commands on a CI runner when an affected Nx command is run, with the credentials available to that job.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203