Repository navigation
Update dependency nx to v23.2.1 [SECURITY] - #1036
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Comment |
renovate
Bot
force-pushed
the
renovate/npm-nx-vulnerability
branch
from
October 7, 2026 07:37
7aa2a01 to
de663b2
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
23.2.0→23.2.1Nx: Path traversal in nx migrate package-migrations extraction
CVE-2026-104853 / GHSA-hrvq-x7jp-36xv
More information
Details
Summary
nx migratereads each target package'snx-migrations.migrationsvalue from its manifest and extracts the referenced file to a path built by joining that value onto a temporary directory. The value is never validated, so a package whosemigrationsfield contains..segments (or an absolute path) steers the extraction to write outside the temporary directory. A hostile package — or any package pulled in transitively through a trusted package'spackageGroup— can write attacker-controlled content, or truncate an existing file, anywhere the running user can write. This happens during migration planning, before the user reviews the migration list and before--run-migrations, so it does not require the user to approve or execute anything.Most workspaces need no action. By default
nx migratedoes not run the nx installed in your workspace — it installsnx@latestinto a temporary directory and performs the upgrade planning, including this extraction, with that copy. Now that a patched nx is the latest release, a defaultnx migraterun is unaffected whatever version the workspace has installed. The installed version only runs, and is only then exposed, when that hand-off is bypassed — see Remediation.Severity
Exploitable when the victim runs
nx migrateagainst a package the attacker controls, directly or through a trusted package'spackageGroup. The primary impact is a file write with attacker-controlled content and no path confinement; overwriting an auto-loaded file (a shell rc, a git hook, a CI script) escalates that write to code execution. There is no known evidence of exploitation in the wild.Affected & Patched Versions
nx>= 13.10.0, < 22.7.10;>= 23.0.0, < 23.2.122.7.10,23.2.1Every version in the ranges above is affected. The lower bound is 13.10.0, the first release where
nx migrateextracted a package's migrations file from its tarball; earlier versions resolved migrations without that extraction.Remediation
If you run
nx migratenormally, there is nothing to do. It resolves and runs the latest nx, which is patched, so your workspace's own nx version does not matter for this flaw.Upgrade only if you bypass that hand-off and run the workspace's nx instead — that is, if you set
NX_USE_LOCALorNX_MIGRATE_USE_LOCAL, pinNX_MIGRATE_CLI_VERSIONto an affected version, resume an existing run with--run-id, or run where the temporary install fails andnx migratefalls back to the local nx. In those cases upgrade to 22.7.10 (22.x line) or 23.2.1 (23.x line) or later:The fix is a drop-in — no configuration changes are required, and no legitimate
migrationsvalue is affected (real packages reference./migrations.jsonor another path within their own directory, all of which remain valid). Either way, do not runnx migrateagainst packages, orpackageGroupmembers, that you do not trust.Details
While planning an upgrade,
nx migrateextracts each target package's migrations file to a destination built by joining the package's ownnx-migrations.migrationsvalue onto a temporary directory. That value is read from the manifest without validation, and it is handled asymmetrically: the name Nx matches against the archive entries is normalized (so its..segments collapse), while the destination path it writes to is a raw join that keeps the..segments and resolves outside the temporary directory. Because the attacker controls the tarball, they name their entry to equal the normalized form; the match then succeeds and the bytes are written to the un-normalized, escaping destination. The normalization is not a defence — it only dictates what the attacker must name their entry.The same value also seeds the directory used for prompt-file extraction, which has the same shape, so both writes are steerable from the one field.
Two distinct primitives fall out of this:
migrationsat an existing file empties that file even when no tar entry matches — no crafted archive required.Credits
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nrwl/nx (nx)
v23.2.1Compare Source
23.2.1 (2026-09-09)
🚀 Features
🩹 Fixes
❤️ Thank You
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.