Intel

AIKIDO-2026-504993

nx is vulnerable to Local Privilege Escalation

Local Privilege EscalationGHSA-w3vv-58gj-gw77 Published Today

85

High Risk

This Affects:

JSnx
14.6.0 - 22.7.8
Fixed in 22.7.9
23.0.0 - 23.1.1
Fixed in 23.1.2
Are you affected? Scan for Free

TL;DR

The Nx daemon and isolated plugin worker create their Unix domain sockets in a subdirectory of the shared OS temp directory with default permissions, so any other local user on the same machine can connect to them. The daemon accepts a PROCESS_IN_BACKGROUND request that names a module to load and invokes its default export, so a peer that can reach the socket can turn that connection into code execution under the daemon's user. The fix moves sockets into an ownership-checked private directory with restrictive permissions and scopes messages to the workspace.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range on a machine or container shared with other local users.

Background info

nx is vulnerable to Local Privilege Escalation in versions 14.6.0 - 22.7.8 and 23.0.0 - 23.1.1.

How to fix this

Upgrade the nx library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform