{"id":"GHSA-w2vw-w76x-qr89","summary":"Nx: OS command injection via git revisions and remote refs","details":"## Summary\n\nNx core builds several `git` invocations as shell command strings with untrusted values interpolated into them, so a value that should be a git revision or ref is parsed by `/bin/sh` instead. Two entry points are reachable by an attacker: `affected` commands, where `defaultBase` / `affected.defaultBase` from `nx.json` (and the `NX_BASE` / `NX_HEAD` environment variables) reach `git merge-base` and `git diff`; and `nx import`, where a branch name advertised by a remote repository reaches `git fetch`, `git checkout`, and `git config`. In both cases an attacker who controls a repository — or who opens a pull request against one — gets arbitrary command execution on the machine of anyone who runs an ordinary Nx command against it, including CI runners.\n\nThe `affected` path is the more serious of the two. `nx affected` and `nx show projects --affected` run constantly in CI, so a pull request that changes nothing but `nx.json` is enough to execute code on the runner with whatever credentials that job holds.\n\n## Severity\n\nExploitable by anyone who controls repository content — a fork's pull request, or a repository the victim clones — that the victim then runs an ordinary `nx affected` or `nx import` against; no access to the victim's machine is required. We have no evidence of exploitation in the wild.\n\n## Affected & Patched Versions\n\n| Package | Vulnerable | Patched |\n| --- | --- | --- |\n| `nx` | `\u003e= 14.0.0, \u003c 22.7.8`; `\u003e= 23.0.0, \u003c 23.1.1` | `22.7.8`, `23.1.1` |\n\nTreat every version below the patched ones as affected.\n\n## Remediation\n\nUpgrade to **22.7.8** (22.x line) or **23.1.1** (23.x line) or later:\n\n```\nnx migrate 23.1.1\n```\n\nThe fix is a drop-in — no configuration changes are required. If you cannot upgrade, treat `nx.json` from untrusted sources as executable content, do not run `affected` commands against pull requests you have not reviewed, and do not run `nx import` against repositories you do not trust.\n\n## Details\n\n### `affected` commands\n\nNx computes the merge base and the changed-file set by building `git merge-base` and `git diff` command lines as strings and running them through a shell. The base and head revisions in those strings come from `nx.json`'s `defaultBase` / `affected.defaultBase` or from the `NX_BASE` / `NX_HEAD` environment variables, and a related code path reads file contents with `git show \u003crevision\u003e:\u003cpath\u003e` the same way. Because a shell parses the whole line, a revision value containing shell syntax is executed rather than passed to `git`.\n\nThe revisions are wrapped in double quotes, which looks protective but is not: POSIX shells still perform command substitution inside double quotes, so a value of `$(…)` runs without needing to break out of the quotes.\n\n### `nx import`\n\nThe `GitRepository` helper runs every git operation — `fetch`, `checkout`, `reset`, `config`, and others — by interpolating its arguments into a shell command string. The untrusted argument is a branch name: `nx import` lists the branches a remote advertises, offers them to the user to choose from, and feeds the chosen name back into those commands. A hostile repository controls the names of its own branches, so it controls the command that runs when one is selected.\n\n\n## Credits\n\n- **Arkadiusz Marta** (RE:SOURCE) — Reporter","modified":"2026-10-05T23:45:07.420845004Z","published":"2026-10-05T23:29:06Z","database_specific":{"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-05T23:29:06Z","nvd_published_at":null,"cwe_ids":["CWE-78","CWE-88"]},"references":[{"type":"WEB","url":"https://github.com/nrwl/nx/security/advisories/GHSA-w2vw-w76x-qr89"},{"type":"WEB","url":"https://github.com/nrwl/nx/pull/36348"},{"type":"WEB","url":"https://github.com/nrwl/nx/pull/36379"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/11ab38573478172109bb5306cb30ca4af246caf0"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/4159295a037fdbd8e7f44a33a19d85ab3792415b"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/9ce184a04d2098a4797c8b0d6877ee079b751abf"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/c12850ce7b364db08e325c13541641d754db7123"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/cd9b3c068e17adc9c1722b35b9ca962b98542c20"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/cf996496bbad727362d48292b50fafc8c3665847"},{"type":"PACKAGE","url":"https://github.com/nrwl/nx"},{"type":"WEB","url":"https://github.com/nrwl/nx/releases/tag/22.7.8"},{"type":"WEB","url":"https://github.com/nrwl/nx/releases/tag/23.1.1"}],"affected":[{"package":{"name":"nx","ecosystem":"npm","purl":"pkg:npm/nx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"14.0.0"},{"fixed":"22.7.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-w2vw-w76x-qr89/GHSA-w2vw-w76x-qr89.json"}},{"package":{"name":"nx","ecosystem":"npm","purl":"pkg:npm/nx"},"ranges":[{"type":"SEMVER","events":[{"introduced":"23.0.0"},{"fixed":"23.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-w2vw-w76x-qr89/GHSA-w2vw-w76x-qr89.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}