GPU VulnDB

Database/Control plane, storage & DevOps

Nx @nx/docker: config-controlled shell injection in release commands executes code in the release job

CVSS 7.3CVE-2026-104859Control plane, storage & DevOpscurated

Impact

The @nx/docker release pipeline builds its docker tag, image lookup and docker push invocations as shell command strings and interpolates the repository's own release.docker.repositoryName and registryUrl values into them before handing them to /bin/sh -c. Anyone who can change Nx configuration - including via a pull request - can therefore run arbitrary commands with the privileges of the release job when nx release version or nx release publish runs, which is where registry credentials and cloud tokens live. Dry-run publishing is not a safe harbour: the vulnerable pre-check command still executes. For an operator this is a build-and-push supply-chain exposure: the stolen credentials are the ones that write container images the GPU fleet then pulls and runs, so the blast radius is every node that consumes images from that registry.

Who can reach it

Anyone who can influence Nx configuration in the repository - a contributor opening a pull request against a pipeline that runs nx release on untrusted branches, or anyone with commit access. No authentication to the runner itself is needed; the CI job executes the attacker's config.

What to do

Upgrade Nx to 22.7.8 or 23.1.1 (affected: 21.4.0 up to 22.7.8, and 23.0.0 up to 23.1.1). This is a dependency bump and a CI re-run, not a fleet action - no node maintenance. Until the bump lands, stop running nx release (including dry runs) on pull-request-triggered workflows and keep registry and cloud credentials out of jobs that build untrusted branches; rotate any registry or cloud tokens that were exposed to such jobs.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.