Vulnerability GHSA-6vc5-vf29-ffr2

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
7 hours ago
October 05, 2026 at 11:29 PM UTC
@nx/docker: OS command injection in the @nx/docker release pipeline
21.4.0 - 22.7.7 and 23.0.0 - 23.1.0
21.4.0 - 22.7.7 and 23.0.0 - 23.1.0

Summary

@nx/docker: OS command injection in the @nx/docker release pipeline

Details

Summary

The @nx/docker release pipeline builds its docker invocations as shell command strings, interpolating release.docker.repositoryName and registryUrl from Nx configuration into them. Because those strings are handed to /bin/sh -c, a crafted repository or registry name executes as a command during nx release version and nx release publish. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.

Severity

Exploitable when someone runs a Docker release against attacker-supplied configuration, with high impact because release jobs hold publishing credentials. There is no known evidence of exploitation in the wild.

Affected & Patched Versions

Package Vulnerable Patched
@nx/docker >= 21.4.0, < 22.7.8; >= 23.0.0, < 23.1.1 22.7.8, 23.1.1

Every published @nx/docker release before the patched versions is affected.

[!IMPORTANT] --dry-run does not protect you: one of the injected commands runs before the dry-run check, so even a dry-run publish reaches a shell.

Remediation

Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:

nx migrate 23.1.1

The fix is a drop-in and requires no configuration change. If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before your next publish, since the composed reference is read back from disk.

Details

Several docker commands in the release pipeline (docker tag during nx release version; the image existence check and docker push during nx release publish) are built as shell command strings with the image reference interpolated in. The reference is composed from the project's release.docker repositoryName and registryUrl, so a value containing shell syntax is executed rather than passed to docker.

Credits

  • Arkadiusz Marta (RE:SOURCE) — Reporter

Impacted packages

Timeline

Published
7 hours ago
October 05, 2026 at 11:29 PM UTC
Fixed (23.1.1)
2 months ago
July 30, 2026 at 10:39 PM UTC
Fixed (22.7.8)
Unknown
Unknown
Last Modified
7 hours ago
October 05, 2026 at 11:45 PM UTC