nx is vulnerable to Path Traversal
58
Medium Risk
nx migrate extracts a target package's migrations file to a destination built by joining the package's nx-migrations.migrations manifest value onto a temporary directory, and that value is read without validation. The matching logic normalizes .. segments while the write path keeps them, so a crafted manifest value can truncate an existing file the running user can access or write attacker-controlled tarball content outside the temporary directory. The fix validates that the migrations path stays inside the temporary directory before extraction.
You are affected if you are using a version that falls within the vulnerable range and you run nx migrate against a package manifest you do not fully trust.
nx is vulnerable to Path Traversal in versions 13.10.0 - 22.7.9 and 23.0.0 - 23.2.0.
Upgrade the nx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.