highVulnerability

GHSA-w2vw-w76x-qr89

## Summary Nx core builds several `git` invocations as shell command strings with untrusted values interpolated into them, so a value that should be a git revision or ref is parsed by `/bin/sh` instead. Two entry points are reachable by an attacker: `affected` commands, where `defaultBase` / `affected.defaultBase` from `nx.json` (and the `NX_BASE` / `NX_HEAD` environment variables) reach `git merge-base` and `git diff`; and `nx import`, where a branch name advertised by a remote repository reaches `git fetch`, `git checkout`, and `git config`. In both cases an attacker who controls a repository — or who opens a pull request against one — gets arbitrary command execution on the machine of anyone who runs an ordinary Nx command against it, including CI runners. The `affected` path is the more serious of the two. `nx affected` and `nx show projects --affected` run constantly in CI, so a pull request that changes nothing but `nx.json` is enough to execute code on the runner with whatever credentials that job holds. ## Severity Exploitable by anyone who controls repository content — a fork's pull request, or a repository the victim clones — that the victim then runs an ordinary `nx affected` or `nx import` against; no access to the victim's machine is required. We have no evidence of exploitation in the wild. ## Affected & Patched Versions | Package | Vulnerable | Patched | | --- | --- | --- | | `nx` | `>= 14.0.0, < 22.7.8`; `>= 23.0.0, < 23.1.1` | `22.7.8`, `23.1.1` | Treat every version below the patched ones as affected. ## Remediation Upgrade to **22.7.8** (22.x line) or **23.1.1** (23.x line) or later: ``` nx migrate 23.1.1 ``` The fix is a drop-in — no configuration changes are required. If you cannot upgrade, treat `nx.json` from untrusted sources as executable content, do not run `affected` commands against pull requests you have not reviewed, and do not run `nx import` against repositories you do not trust. ## Details ### `affected` commands Nx com

Properties

ghsa_id
GHSA-w2vw-w76x-qr89
summary
Nx: OS command injection via git revisions and remote refs
severity
high
last_source
GitHub Advisory Database
cve_id
GHSA-w2vw-w76x-qr89
signal_observed_at
2026-10-06T02:58:31+00:00
is_ghsa_only
true
retrieved_at
2026-10-06T03:05:59+00:00
ghsa_published
2026-10-05T23:29:06Z
source_url
https://github.com/advisories/GHSA-w2vw-w76x-qr89
ghsa_updated
2026-10-05T23:29:07Z

Related Entities (5)

HAS_WEAKNESS (2)

→[Weakness]Improper Neutralization of Argument Delimiters in a Command ('Argument Injection')
→[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

REPORTED_BY (1)

→[Source]GitHub Advisory Database

VULNERABLE_TO (1)

←[Software]npm/nx

AFFECTS (1)

→[Software]npm/nx

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-w2vw-w76x-qr89 — Ninja Signal Threat Intelligence | Ninja Signal