@nx/docker is vulnerable to OS Command Injection
73
High Risk
The Docker release executors build the image-existence check, docker tag, and docker push commands as shell strings, interpolating a project's repositoryName and registryUrl settings during nx release version and nx release publish. A configuration value containing shell syntax runs as an arbitrary command before Docker itself executes, and --dry-run does not prevent it because the injected command runs ahead of that check. The fix spawns Docker without a shell so image references are passed as literal arguments.
You are affected if you are using a version that falls within the vulnerable range and you run nx release version or nx release publish for a Docker-based project.
@nx/docker is vulnerable to OS Command Injection in versions 21.4.0 - 22.7.7 and 23.0.0 - 23.1.0.
Upgrade the @nx/docker library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.