
nx has a Zip-Slip bug in its self-hosted HTTP remote cache. It extracts tar entries from downloaded cache artifacts without checking the path, so a malicious or MITM cache server can write files anywhere on disk. Escalates to RCE. Fixed in 22.7.7 / 23.0.2. CVE-2026-71476 / GHSA-vp3h-ghgh-jr7g https://hol.org/guard/security/cves
Post summary
A Zip‑Slip path‑traversal flaw in NX’s HTTP remote cache allows arbitrary file writes and remote code execution, and the issue has been resolved in releases 22.7.7 and 23.0.2.

