Database/Control plane, storage & DevOps
Nx @nx/docker: config-controlled shell injection in release commands executes code in the release job
Impact
The @nx/docker release pipeline builds its docker tag, image lookup and docker push invocations as shell command strings and interpolates the repository's own release.docker.repositoryName and registryUrl values into them before handing them to /bin/sh -c. Anyone who can change Nx configuration - including via a pull request - can therefore run arbitrary commands with the privileges of the release job when nx release version or nx release publish runs, which is where registry credentials and cloud tokens live. Dry-run publishing is not a safe harbour: the vulnerable pre-check command still executes. For an operator this is a build-and-push supply-chain exposure: the stolen credentials are the ones that write container images the GPU fleet then pulls and runs, so the blast radius is every node that consumes images from that registry.
Who can reach it
Anyone who can influence Nx configuration in the repository - a contributor opening a pull request against a pipeline that runs nx release on untrusted branches, or anyone with commit access. No authentication to the runner itself is needed; the CI job executes the attacker's config.
What to do
Upgrade Nx to 22.7.8 or 23.1.1 (affected: 21.4.0 up to 22.7.8, and 23.0.0 up to 23.1.1). This is a dependency bump and a CI re-run, not a fleet action - no node maintenance. Until the bump lands, stop running nx release (including dry runs) on pull-request-triggered workflows and keep registry and cloud credentials out of jobs that build untrusted branches; rotate any registry or cloud tokens that were exposed to such jobs.
References
Related entries
- ansible.posix authorized_key: a symlink under a user's ~/.ssh redirects a root chown to any pathCVE-2026-11837 · ansible.posix collection - authorized_key module (keyfile() ownership handling)High
- GitLab EE: developer-role user can run arbitrary commands in CI via attacker-controlled agent configCVE-2026-18252 · GitLab EE CI (Claude agent processing configuration from a user-controlled source)High
- Apache Airflow 3.3.0: Dag author reaches arbitrary imports in the scheduler via next_kwargs deserializationCVE-2026-67260 · Apache Airflow scheduler (awaiting_input sweep, next_kwargs deserialization)High
- Jenkins: session is not rotated on remember-me login, allowing session fixation against any userCVE-2026-84652 · Jenkins core (remember-me authentication, session handling)High
- Renovate gomod manager: shell metacharacters in a dependency name run commands as the Renovate userCVE-2026-88885 · Renovate (gomod manager, import-path update with binarySource=docker)High
- Renovate Mix manager: unescaped organization parameter lets a package name run commands as the Renovate userCVE-2026-88888 · Renovate (Mix manager, private dependency organization parameter)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.