Vendor
OS Command Injection in Nx via Git Revisions and Remote Refs
2 TTPsThe Nx build system contains OS command injection vulnerabilities in `nx affected` and `nx import` commands, allowing attackers to execute arbitrary code via malicious git revision strings or remote branch names.
OS Command Injection in @nx/docker Release Pipeline
1 TTP 1 CVEThe @nx/docker package is vulnerable to OS command injection via insecure shell command construction, allowing arbitrary command execution during release processes through malicious configuration inputs.
Zip-Slip Vulnerability in Nx Self-Hosted Remote Cache
1 TTPA Zip-Slip vulnerability in the Nx self-hosted HTTP remote cache allows a malicious cache server to write files to arbitrary locations on a client machine, leading to potential remote code execution.
Nx Console Compromised Extension Harvesting Credentials (CVE-2026-48027)
2 rules 1 TTP 1 CVENx Console contained an embedded malicious code vulnerability (CVE-2026-48027) which allowed a malicious version of the extension to be published and harvest credentials from disk and memory.
DNS Kerberos Coercion Attempt Detection
3 rules 3 TTPs 4 CVEs 4 IOCsThis brief details the detection of DNS-based Kerberos coercion attacks, where adversaries inject marshaled credential structures into DNS records to spoof SPNs and redirect authentication, as seen in CVE-2025-33073, using Suricata and Sysmon event ID 22.