nx is vulnerable to Exposure of Sensitive System Information
82
High Risk
Affected versions of this package are vulnerable to exposure of sensitive system information. Sensitive keys such as NX_CLOUD_ENCRYPTION_KEY (e2e encryption token) or NX_CLOUD_ACCESS_TOKEN (access token to the cloud CI solution), when set in the environment variables, can be exposed during the bundling process.
You are affected if you are using a version of this package >=12.3.5 and = 18.1.2 and NX_CLOUD_ENCRYPTION_KEY or NX_CLOUD_ACCESS_TOKEN are set in the environment variables
nx is vulnerable to Exposure of Sensitive System Information in versions 12.3.5 - 18.1.2.
Upgrade the nx library to the patch version or remove NX_CLOUD_ENCRYPTION_KEY and NX_CLOUD_ACCESS_TOKEN from the environment variables.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

SOC 2Compliant
ISO 27001Compliant