npm package report

Is @nx/docker safe?

1 known vulnerability, worst severity HIGH.

// reach

3 direct dependencies

none carry a known advisory

    0 packages depend on it

    an advisory here reaches each of them

      Create a free accountfor every dependency path, dependent and what to upgrade
      // ai model usage

      Tracked for PyPI packages. HuggingFace models declare Python dependencies, so npm packages are not covered.


      cvss
      0.0
      high

      severity out of 10

      epss
      0.00%
      low

      chance of exploitation in 30 days, 4th percentile of all CVEs

      xyz score
      not scored

      CyberXYZ composite out of 10

      fig. 01 — GHSA-6vc5-vf29-ffr2, the advisory selected below

      // 1 advisories

      GHSA-6vc5-vf29-ffr2

      HIGHCVE-2026-104859
      // summary

      The @nx/docker release pipeline builds its docker invocations as shell command strings, interpolating release.docker.repositoryName and registryUrl from Nx configuration into them. Because those strings are handed to /bin/sh -c, a crafted repository or registry name executes as a command during nx release version and nx release publish. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.

      // severity

      Exploitable when someone runs a Docker release against attacker-supplied configuration, with high impact because release jobs hold publishing credentials. There is no known evidence of exploitation in the wild.

      // affected & patched versions

      | Package | Vulnerable | Patched | | --- | --- | --- | | @nx/docker | >= 21.4.0, = 23.0.0, [!IMPORTANT] > --dry-run does not protect you: one of the injected commands runs before the dry-run check, so even a dry-run publish reaches a shell.

      // remediation

      Upgrade to 22.7.8 (22.x line) or 23.1.1 (23.x line) or later:

      nx migrate 23.1.1

      The fix is a drop-in and requires no configuration change. If you have run nx release version with a configuration you do not trust, delete the generated Docker version file before your next publish, since the composed reference is read back from disk.

      // details

      Several docker commands in the release pipeline (docker tag during nx release version; the image existence check and docker push during nx release publish) are built as shell command strings with the image reference interpolated in. The reference is composed from the project's release.docker repositoryName and registryUrl, so a value containing shell syntax is executed rather than passed to docker.

      // credits
      • Arkadiusz Marta (RE:SOURCE) — Reporter
      // cvss v4.0 vector

      CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

      Attack vector
      Local
      Attack complexity
      Low
      Attack requirements
      Present
      Privileges required
      None
      User interaction
      Passive
      Confidentiality (vulnerable system)
      High
      Integrity (vulnerable system)
      High
      Availability (vulnerable system)
      High
      Confidentiality (subsequent systems)
      None
      Integrity (subsequent systems)
      None
      Availability (subsequent systems)
      None

      Checked 2026-10-06 at 02:02 UTC. The most recent advisory here was published 2026-10-05. Updated continuously from NVD, GHSA, OSV and CNA feeds.

      Think a verdict here is wrong? Tell us — we respond within 2 business days.