AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-104853.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSMEDIUM / 5.8CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSUndergoing AnalysisModified Oct 02, 2026

Disclosure summary

Nx is a monorepo solution for TypeScript and polyglot codebases. From 13.10.0 until 22.7.10 and 23.2.1, Nx migration planning reads the nx-migrations.migrations value from a target package manifest without validating that it is a contained relative path. A hostile direct dependency or a package introduced through a trusted package's packageGroup can supply .. segments or an absolute path, causing nx migrate to join an escaping destination onto its temporary directory. The migration archive can then write attacker-controlled bytes outside the temporary directory, while opening the destination stream can truncate an existing writable file even when no archive entry matches. This occurs during migration planning before review of the migration list or use of --run-migrations; the vulnerable installed Nx copy is reached when the normal nx@latest handoff is bypassed with NX_USE_LOCAL, NX_MIGRATE_USE_LOCAL, NX_MIGRATE_CLI_VERSION, --run-id, or fallback after a temporary-install failure. This issue is fixed in versions 22.7.10 and 23.2.1.

Source-reported weakness categories

CWE-22, CWE-73

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-hrvq-x7jp-36xv

Open original source · Updated Oct 05, 2026

Nx: Path traversal in nx migrate package-migrations extraction

Source severity: MEDIUM / 5.8

EcosystemPackageAffected rangeFirst patched
npmnx>= 13.10.0, < 22.7.1022.7.10
npmnx>= 23.0.0, < 23.2.123.2.1
NIST National Vulnerability Database · NVD-CVE-2026-104853

Open original source · Updated Oct 02, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-02T13:17:03-04:00
MODIFIED 2026-10-02T14:17:01-04:00
INGESTED 2026-10-06T11:45:30-04:00