AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-104854.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 8.5CVSS 4.0 · security-advisories@github.com
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSUndergoing AnalysisModified Oct 02, 2026

Disclosure summary

Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.

Source-reported weakness categories

CWE-269, CWE-732

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-w3vv-58gj-gw77

Open original source · Updated Oct 05, 2026

Nx daemon and plugin worker sockets are accessible to other local users

Source severity: HIGH / 8.5

EcosystemPackageAffected rangeFirst patched
npmnx>= 14.6.0, < 22.7.922.7.9
npmnx>= 23.0.0, < 23.1.223.1.2
NIST National Vulnerability Database · NVD-CVE-2026-104854

Open original source · Updated Oct 02, 2026

Only CPE matches marked vulnerable=true are indexed. AND/OR platform conditions must be checked in the original NVD record.

Original records & references

PUBLISHED 2026-10-02T13:17:04-04:00
MODIFIED 2026-10-02T14:17:01-04:00
INGESTED 2026-10-06T11:45:30-04:00