{"id":"GHSA-6vc5-vf29-ffr2","summary":"@nx/docker: OS command injection in the @nx/docker release pipeline","details":"## Summary\n\nThe `@nx/docker` release pipeline builds its `docker` invocations as shell command strings, interpolating `release.docker.repositoryName` and `registryUrl` from Nx configuration into them. Because those strings are handed to `/bin/sh -c`, a crafted repository or registry name executes as a command during `nx release version` and `nx release publish`. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.\n\n## Severity\n\nExploitable when someone runs a Docker release against attacker-supplied configuration, with high impact because release jobs hold publishing credentials. There is no known evidence of exploitation in the wild.\n\n## Affected & Patched Versions\n\n| Package | Vulnerable | Patched |\n| --- | --- | --- |\n| `@nx/docker` | `\u003e= 21.4.0, \u003c 22.7.8`; `\u003e= 23.0.0, \u003c 23.1.1` | `22.7.8`, `23.1.1` |\n\nEvery published `@nx/docker` release before the patched versions is affected.\n\n\u003e [!IMPORTANT]\n\u003e `--dry-run` does not protect you: one of the injected commands runs before the dry-run check, so even a dry-run publish reaches a shell.\n\n## Remediation\n\nUpgrade to **22.7.8** (22.x line) or **23.1.1** (23.x line) or later:\n\n```\nnx migrate 23.1.1\n```\n\nThe fix is a drop-in and requires no configuration change. If you have run `nx release version` with a configuration you do not trust, delete the generated Docker version file before your next publish, since the composed reference is read back from disk.\n\n## Details\n\nSeveral `docker` commands in the release pipeline (`docker tag` during `nx release version`; the image existence check and `docker push` during `nx release publish`) are built as shell command strings with the image reference interpolated in. The reference is composed from the project's `release.docker` `repositoryName` and `registryUrl`, so a value containing shell syntax is executed rather than passed to `docker`.\n \n\n## Credits\n\n- **Arkadiusz Marta** (RE:SOURCE) — Reporter","aliases":["CVE-2026-104859"],"modified":"2026-10-05T23:45:07.779805068Z","published":"2026-10-05T23:29:13Z","database_specific":{"nvd_published_at":"2026-10-02T18:17:02Z","cwe_ids":["CWE-78"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2026-10-05T23:29:13Z"},"references":[{"type":"WEB","url":"https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104859"},{"type":"WEB","url":"https://github.com/nrwl/nx/pull/36505"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/6d60eed061f050e0d5af509a1f5a07c707f09865"},{"type":"WEB","url":"https://github.com/nrwl/nx/commit/b587441fd8da28c5db37edb0826554e0060dc81b"},{"type":"PACKAGE","url":"https://github.com/nrwl/nx"}],"affected":[{"package":{"name":"@nx/docker","ecosystem":"npm","purl":"pkg:npm/%40nx/docker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"21.4.0"},{"fixed":"22.7.8"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6vc5-vf29-ffr2/GHSA-6vc5-vf29-ffr2.json"}},{"package":{"name":"@nx/docker","ecosystem":"npm","purl":"pkg:npm/%40nx/docker"},"ranges":[{"type":"SEMVER","events":[{"introduced":"23.0.0"},{"fixed":"23.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/10/GHSA-6vc5-vf29-ffr2/GHSA-6vc5-vf29-ffr2.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}