nx is vulnerable to Local Privilege Escalation
85
High Risk
The Nx daemon and isolated plugin worker create their Unix domain sockets in a subdirectory of the shared OS temp directory with default permissions, so any other local user on the same machine can connect to them. The daemon accepts a PROCESS_IN_BACKGROUND request that names a module to load and invokes its default export, so a peer that can reach the socket can turn that connection into code execution under the daemon's user. The fix moves sockets into an ownership-checked private directory with restrictive permissions and scopes messages to the workspace.
You are affected if you are using a version that falls within the vulnerable range on a machine or container shared with other local users.
nx is vulnerable to Local Privilege Escalation in versions 14.6.0 - 22.7.8 and 23.0.0 - 23.1.1.
Upgrade the nx library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.