The core Nx plugin contains the core functionality of Nx like the project graph, nx commands and task orchestration.
68%
Total Score
100
3
91
40
100
| Title | Versions | Severity |
|---|---|---|
CVE-2026-71476 nx is vulnerable to Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in versions 20.8.0 - 22.7.7 and 23.0.0 - 23.0.2. | 20.8.0 - 22.7.723.0.0 - 23.0.2 | High |
AIKIDO-2026-373135 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. nx is vulnerable to Command Injection in versions 13.10.0 - 22.7.7 and 23.0.0 - 23.1.0. | 13.10.0 - 22.7.723.0.0 - 23.1.0 | Medium |
CVE-2026-54753 nx is vulnerable to Exposed Dangerous Method or Function in versions 17.0.4 - 22.7.2 and 23.0.0-beta.0 - 23.0.0-beta.2. | 17.0.4 - 22.7.223.0.0-beta.0 - 23.0.0-beta.2 | Medium |
AIKIDO-2026-477013 nx is vulnerable to Path Traversal in versions 20.8.0 - 22.7.6 and 23.0.0 - 23.0.1. | 20.8.0 - 22.7.623.0.0 - 23.0.1 | High |
AIKIDO-2026-11005 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. nx is vulnerable to Information Disclosure in versions 18.0.0 - 22.7.1. | 18.0.0 - 22.7.1 | Medium |
| Dependency | Last Release | Score |
|---|---|---|
bl Version 4.1.0 | — | — |
ms Version 2.1.3 | — | — |
ejs Version 5.0.1 | — | — |
ora Version 5.4.1 | — | — |
tmp Version 0.2.7 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant