Vulnerability MAL-2025-41443
Unknown
UNKNOWN RISK
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
1 year ago
August 27, 2025 at 04:42 PM UTC
Malicious code in nx (npm)
20.9.0 - 20.12.0 and 21.5.0 - 21.8.0
20.9.0 - 20.12.0 and 21.5.0 - 21.8.0
Summary
Malicious code in nx (npm)
Details
References
- ADVISORY — github.com
- REPORT — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — github.com
- WEB — x.com
- ADVISORY — nvd.nist.gov
- WEB — access.redhat.com
- WEB — access.redhat.com
- WEB — bugzilla.redhat.com
- WEB — www.stepsecurity.io
- WEB — www.wiz.io
- WEB — github.com
- WEB — www.npmjs.com
- ADVISORY — github.com
Related Vulnerabilities
Other vulnerabilities affecting the same packages
High Risk
8 hours ago
Nx: OS command injection via git revisions and remote refs
14.0.0 - 22.7.7 and 23.0.0 - 23.1.0 GHSA-w2vw-w76x-qr89
14.0.0 - 22.7.7 and 23.0.0 - 23.1.0 GHSA-w2vw-w76x-qr89
High Risk
8 hours ago
Nx daemon and plugin worker sockets are accessible to other local users
14.6.0 - 22.7.8 and 23.0.0 - 23.1.1 GHSA-w3vv-58gj-gw77
14.6.0 - 22.7.8 and 23.0.0 - 23.1.1 GHSA-w3vv-58gj-gw77
Medium Risk
8 hours ago
Nx: Path traversal in nx migrate package-migrations extraction
13.10.0 - 22.7.9 and 23.0.0 - 23.2.0 GHSA-hrvq-x7jp-36xv
13.10.0 - 22.7.9 and 23.0.0 - 23.2.0 GHSA-hrvq-x7jp-36xv
High Risk
2 months ago
Nx: Zip-Slip in the self-hosted remote cache
20.8.0 - 22.7.6 and 23.0.0 - 23.0.1 GHSA-vp3h-ghgh-jr7g
20.8.0 - 22.7.6 and 23.0.0 - 23.0.1 GHSA-vp3h-ghgh-jr7g
Medium Risk
2 months ago
`nx graph` dev server permissive CORS policy
17.0.4 - 22.7.1 and 23.0.0-beta.0 - 23.0.0-beta.1 GHSA-g2r8-wvmj-jf5w
17.0.4 - 22.7.1 and 23.0.0-beta.0 - 23.0.0-beta.1 GHSA-g2r8-wvmj-jf5w
Impacted packages
Timeline
Published
1 year ago
August 27, 2025 at 04:42 PM UTC
Last Modified
2 months ago
July 28, 2026 at 05:21 AM UTC