OFFLINE
Awaiting data
Security intelligence
MajorCritical vulnerability

Nx: OS command injection via git revisions and remote refs

GitHub Advisories · officialPublished Oct 5, 2026Risk 37/100

## Summary Nx core builds several `git` invocations as shell command strings with untrusted values interpolated into them, so a value that should be a git revision or ref is parsed by `/bin/sh` instead. Two entry points are reachable by an attacker: `affected` commands, where `defaultBase` / `affected.defaultBase` from `nx.json` (and the `NX_BASE` / `NX_HEAD` environment variables) reach `git merge-base` and `git diff`; and `nx import`, where a branch name advertised by a remote repository reaches `git fetch`, `git checkout`, and `git config`. In both cases an attacker who controls a repository — or who opens a pull request against one — gets arbitrary command execution on the machine of anyone who runs an ordinary Nx command against it, including CI runners. The `affected` path is the more serious of the two. `nx affected` and `nx show projects --affected` run constantly in CI, so a pull request that changes nothing but `nx.json` is enough to execute code on the runner with whatever credentials that job holds. ## Severity Exploitable by anyone who controls repository content — a fork's pull request, or a repository the victim clones — that the victim then runs an ordinary `nx affected` or `nx import` against; no access to the victim's machine is required. We have no evidence of exploitation in the wild. ## Affected & Patched Versions | Package | Vulnerable | Patched | | --- | --- | --- | | `nx` | `>= 14.0.0, < 22.7.8`; `>= 23.0.0, < 23.1.1` | `22.7.8`, `23.1.1` | Treat every version below the patched ones as affected. ## Remediation Upgrade to **22.7.8** (22.x line) or **23.1.1** (23.x line) or later: ``` nx migrate 23.1.1 ``` The fix is a drop-in — no configuration changes are required. If you cannot upgrade, treat `nx.json` from untrusted sources as executable content, do not run `affected` commands against pull requests you have not reviewed, and do not run `nx import` against repositories you do not trust. ## Details ### `affected` commands Nx computes the merge base and the changed-file set by building `git merge-base` and `git diff` command lines as strings and running them through a shell. The base and head revisions in those strings come from `nx.json`'s `defaultBase` / `affected.defaultBase` or from the `NX_BASE` / `NX_HEAD` environment variables, and a related code path reads file contents with `git show <revision>:<path>` the same way. Because a shell parses the whole line, a revision value containing shell syntax is executed rather than passed to `git`. The revisions are wrapped in double quotes, which looks protective but is not: POSIX shells still perform command substitution inside double quotes, so a value of `$(…)` runs without needing to break out of the quotes. ### `nx import` The `GitRepository` helper runs every git operation — `fetch`, `checkout`, `reset`, `config`, and others — by interpolating its arguments into a shell command string. The untrusted argument is a branch name: `nx import` lists the branches a remote advertises, offers them to the user to choose from, and feeds the chosen name back into those commands. A hostile repository controls the names of its own branches, so it controls the command that runs when one is selected. ## Credits - **Arkadiusz Marta** (RE:SOURCE) — Reporter

Upgrade affected packages to a patched version: nx 22.7.8, nx 23.1.1.

Vendor
Not specified
Product
nx
Exploitation
none known
Evidence
official

This record is attributed to GitHub Advisories. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source