{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/@nx/powerpack-gcs-cache/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["nx","@nx/s3-cache","@nx/gcs-cache","@nx/azure-cache","@nx/shared-fs-cache","@nx/powerpack-s3-cache","@nx/powerpack-gcs-cache","@nx/powerpack-azure-cache","@nx/powerpack-shared-fs-cache"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Nx"],"content_html":"\u003cp\u003eNx versions 20.8.0 through 22.7.6 and 23.0.0 through 23.0.1 contain a critical Zip-Slip vulnerability in their self-hosted HTTP remote cache implementation. The vulnerability stems from an insecure extraction routine that fails to validate file paths within downloaded tar archives. By leveraging a compromised or malicious self-hosted remote cache server, an attacker can provide a crafted tar archive containing directory traversal sequences. These sequences cause the client-side Nx extraction logic to write files outside of the intended directory, potentially overwriting critical system files or placing malicious binaries in executable paths. This flaw is specific to self-hosted cache configurations (\u003ccode\u003eNX_SELF_HOSTED_REMOTE_CACHE_SERVER\u003c/code\u003e and related packages); default local caching and Nx Cloud remain unaffected.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eThe attacker gains control of the infrastructure hosting the Nx remote cache server or performs a Man-in-the-Middle (MITM) attack to intercept HTTP traffic.\u003c/li\u003e\n\u003cli\u003eThe Nx client requests a cached task output artifact from the remote cache server.\u003c/li\u003e\n\u003cli\u003eThe malicious server responds with a crafted gzipped tar archive containing entries with directory traversal characters (e.g., ../../).\u003c/li\u003e\n\u003cli\u003eThe Nx client receives the payload and passes it to the vulnerable extraction routine.\u003c/li\u003e\n\u003cli\u003eThe routine joins the untrusted archive entry path to the base output directory without validation.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003etar\u003c/code\u003e extraction process writes the file to an arbitrary location on the client filesystem based on the traversal path.\u003c/li\u003e\n\u003cli\u003eThe attacker targets sensitive locations, such as startup folders or configuration files, to achieve remote code execution upon the next system or application restart.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability poses a high risk to organizations using self-hosted Nx remote caches. Successful exploitation allows for arbitrary file writes with the privileges of the user running the Nx workspace commands. This can lead to full system compromise, exfiltration of sensitive source code or credentials, and persistent remote code execution within the CI/CD pipeline or developer environments.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the \u003ccode\u003enx\u003c/code\u003e core package to versions \u003ccode\u003e22.7.7\u003c/code\u003e or \u003ccode\u003e23.0.2\u003c/code\u003e immediately to patch the insecure extractor.\u003c/li\u003e\n\u003cli\u003eMigrate away from deprecated self-hosted cache packages (\u003ccode\u003e@nx/s3-cache\u003c/code\u003e, \u003ccode\u003e@nx/gcs-cache\u003c/code\u003e, \u003ccode\u003e@nx/azure-cache\u003c/code\u003e, \u003ccode\u003e@nx/shared-fs-cache\u003c/code\u003e, and their Powerpack counterparts) as these remain vulnerable and lack patches.\u003c/li\u003e\n\u003cli\u003eAudit infrastructure hosting remote caches to ensure secure access controls and prevent unauthorized server-side modifications.\u003c/li\u003e\n\u003cli\u003eUse network-level security, such as TLS and mutual authentication, to prevent MITM attacks on the remote cache traffic.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-06T21:29:52Z","date_published":"2026-08-06T21:29:52Z","id":"https://feed.craftedsignal.io/briefs/2026-08-nx-zip-slip/","summary":"A Zip-Slip vulnerability in the Nx self-hosted HTTP remote cache allows a malicious cache server to write files to arbitrary locations on a client machine, leading to potential remote code execution.","title":"Zip-Slip Vulnerability in Nx Self-Hosted Remote Cache","url":"https://feed.craftedsignal.io/briefs/2026-08-nx-zip-slip/"}],"language":"en","title":"CraftedSignal Threat Feed - @Nx/Powerpack-Gcs-Cache","version":"https://jsonfeed.org/version/1.1"}