OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-104854

HIGH · CVSS 8.5 EPSS 0.14% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-10-02 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Nx versions 14.6.0 to 22.7.9 and 23.1.2 are vulnerable due to the creation of Unix domain sockets in shared temporary locations without proper permissions, allowing unprivileged local accounts to connect and potentially execute arbitrary code. This vulnerability can lead to unauthorized access to sensitive workspace data and execution of code as the Nx account, posing a significant risk in multi-user environments such as shared build servers or containers. Organizations using affected versions in collaborative or shared settings should prioritize upgrading to the patched versions 22.7.9 or 23.1.2 to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-104854
Severity
HIGH
CVSS
8.5
EPSS
0.14%

Original NVD Description

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.