CVE-2026-104854

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269CWE-732

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-02: 110-02
Full discourse1 post
  • Upwind Security MDR@UpwindMDR

    🚨High - Nx Daemon Unix Socket Exposure Enables Local Code Execution (CVE-2026-104854) Nx daemon and plugin-worker create Unix domain sockets in shared temp dirs with non-owner-only perms, letting other local users connect unauthenticated. An attacker can send PROCESS_IN_BACKGROUND with a module path to load/execute code as the Nx-running user and access workspace files, project graphs, and task hashes. 👉Affected: nx < 22.7.9 and 23.0.0-23.1.1 | Upgrade to 22.7.9 or 23.1.2

    0000045
    308 followersView on X

Explore more