Skip to content

Update dependency nx to v23.2.1 [SECURITY] - #1036

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nx-vulnerability
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/npm-nx-vulnerability

Conversation

@renovate

@renovate renovate Bot commented Oct 6, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
nx (source) 23.2.0 → 23.2.1 age confidence

Nx: Path traversal in nx migrate package-migrations extraction

CVE-2026-104853 / GHSA-hrvq-x7jp-36xv

More information

Details

Summary

nx migrate reads each target package's nx-migrations.migrations value from its manifest and extracts the referenced file to a path built by joining that value onto a temporary directory. The value is never validated, so a package whose migrations field contains .. segments (or an absolute path) steers the extraction to write outside the temporary directory. A hostile package — or any package pulled in transitively through a trusted package's packageGroup — can write attacker-controlled content, or truncate an existing file, anywhere the running user can write. This happens during migration planning, before the user reviews the migration list and before --run-migrations, so it does not require the user to approve or execute anything.

Most workspaces need no action. By default nx migrate does not run the nx installed in your workspace — it installs nx@latest into a temporary directory and performs the upgrade planning, including this extraction, with that copy. Now that a patched nx is the latest release, a default nx migrate run is unaffected whatever version the workspace has installed. The installed version only runs, and is only then exposed, when that hand-off is bypassed — see Remediation.

Severity

Exploitable when the victim runs nx migrate against a package the attacker controls, directly or through a trusted package's packageGroup. The primary impact is a file write with attacker-controlled content and no path confinement; overwriting an auto-loaded file (a shell rc, a git hook, a CI script) escalates that write to code execution. There is no known evidence of exploitation in the wild.

Affected & Patched Versions
Package Vulnerable Patched
nx >= 13.10.0, < 22.7.10; >= 23.0.0, < 23.2.1 22.7.10, 23.2.1

Every version in the ranges above is affected. The lower bound is 13.10.0, the first release where nx migrate extracted a package's migrations file from its tarball; earlier versions resolved migrations without that extraction.

[!IMPORTANT]
nx migrate normally fetches and runs nx@latest rather than the nx installed in your workspace. The ranges above therefore say where the vulnerable code ships, not who is exposed — it only runs when that hand-off is bypassed.

Remediation

If you run nx migrate normally, there is nothing to do. It resolves and runs the latest nx, which is patched, so your workspace's own nx version does not matter for this flaw.

Upgrade only if you bypass that hand-off and run the workspace's nx instead — that is, if you set NX_USE_LOCAL or NX_MIGRATE_USE_LOCAL, pin NX_MIGRATE_CLI_VERSION to an affected version, resume an existing run with --run-id, or run where the temporary install fails and nx migrate falls back to the local nx. In those cases upgrade to 22.7.10 (22.x line) or 23.2.1 (23.x line) or later:

nx migrate 23.2.1

The fix is a drop-in — no configuration changes are required, and no legitimate migrations value is affected (real packages reference ./migrations.json or another path within their own directory, all of which remain valid). Either way, do not run nx migrate against packages, or packageGroup members, that you do not trust.

Details

While planning an upgrade, nx migrate extracts each target package's migrations file to a destination built by joining the package's own nx-migrations.migrations value onto a temporary directory. That value is read from the manifest without validation, and it is handled asymmetrically: the name Nx matches against the archive entries is normalized (so its .. segments collapse), while the destination path it writes to is a raw join that keeps the .. segments and resolves outside the temporary directory. Because the attacker controls the tarball, they name their entry to equal the normalized form; the match then succeeds and the bytes are written to the un-normalized, escaping destination. The normalization is not a defence — it only dictates what the attacker must name their entry.

The same value also seeds the directory used for prompt-file extraction, which has the same shape, so both writes are steerable from the one field.

Two distinct primitives fall out of this:

  • Truncation — the destination write stream is opened, and truncates, before any tar entry is inspected. So a package that points migrations at an existing file empties that file even when no tar entry matches — no crafted archive required.
  • Controlled write — when a tar entry's name matches, its bytes are written to the escaping destination. The extractor performs no path containment of its own.
Credits
  • Arkadiusz Marta (RE:SOURCE) — Reporter

Severity

  • CVSS Score: 5.8 / 10 (Medium)
  • Vector String: CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:N

References

This data is provided by the GitHub Advisory Database (CC-BY 4.0).


Release Notes

nrwl/nx (nx)

v23.2.1

Compare Source

23.2.1 (2026-09-09)
🚀 Features
🩹 Fixes
  • angular: correct declaration maps and exports of buildable libraries (#​36373, #​36357)
  • core: separate daemon runtime env from graph identity (#​36565, #​36564)
  • core: validate the migrations path before extracting package migrations (#​36887)
  • core: release per-run process listeners and task history results (#​36866)
  • core: read the pnpm 12 min-release-age policy instead of deferring to an install (#​36915, #​36914)
  • core: carry minimumReleaseAge into pruned pnpm deploy output (#​36900, #​36899)
  • core: report how a plugin worker was lost instead of always calling it an exit (#​36894)
  • core: keep the cache in the workspace on CI (#​36922)
  • core: restore the wasm walker imports dropped by a stray cfg attribute (#​36924)
  • core: avoid mutating target options when resolving configurations (#​36934)
  • js: resolve tsconfig to absolute path so ${configDir} paths type-check without baseUrl (#​36445)
  • misc: scan package projects for env vars (#​36847)
  • release: exclude AI coding agents from the changelog Thank You section (#​36892)
  • release: use the release group name when resolving the previous tag for fixed groups (#​36554)
  • repo: provision JDK 17 for Gradle builds with mise (#​36965)
  • repo: guard JAVA17_HOME against an uninstalled JDK (#​36969)
  • rspack: write the normalized cache option in NxAppRspackPlugin (#​36905, #​36878)
❤️ Thank You

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot enabled auto-merge (squash) October 6, 2026 03:54
@coderabbitai

coderabbitai Bot commented Oct 6, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration
  • Configuration used: Organization UI
  • Review profile: CHILL
  • Plan: Advanced
  • Run ID: 22533561-94f5-4098-a499-eb45342433c0

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Comment @coderabbitai help to get the list of available commands.

@renovate
renovate Bot force-pushed the renovate/npm-nx-vulnerability branch from 7aa2a01 to de663b2 Compare October 7, 2026 07:37
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant