@nx/gradle is vulnerable to OS Command Injection
73
High Risk
The Gradle plugin's project-graph analyzer maps every nx.json plugin option into a -P argument and launches the Gradle command through a shell. An option value containing shell syntax runs as an arbitrary command with the privileges of the user running nx, reachable by cloning a hostile repository or checking out a pull request that edits nx.json. The fix spawns Gradle without a shell so option values are passed as literal arguments.
You are affected if you are using a version that falls within the vulnerable range and the @nx/gradle plugin is registered in your workspace.
@nx/gradle is vulnerable to OS Command Injection in versions 21.0.0 - 22.7.8 and 23.0.0 - 23.1.1.
Upgrade the @nx/gradle library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.