Repository navigation
chore(deps): update dependency nx to v23.2.1 [security] - #333
Conversation
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configuration
You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
View your CI Pipeline Execution ↗ for commit 4922c3a
☁️ Nx Cloud last updated this comment at |
commit: |
This PR contains the following updates:
23.2.0→23.2.1Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Nx: Path traversal in nx migrate package-migrations extraction
CVE-2026-104853 / GHSA-hrvq-x7jp-36xv
More information
Details
Summary
nx migratereads each target package'snx-migrations.migrationsvalue from its manifest and extracts the referenced file to a path built by joining that value onto a temporary directory. The value is never validated, so a package whosemigrationsfield contains..segments (or an absolute path) steers the extraction to write outside the temporary directory. A hostile package — or any package pulled in transitively through a trusted package'spackageGroup— can write attacker-controlled content, or truncate an existing file, anywhere the running user can write. This happens during migration planning, before the user reviews the migration list and before--run-migrations, so it does not require the user to approve or execute anything.Most workspaces need no action. By default
nx migratedoes not run the nx installed in your workspace — it installsnx@latestinto a temporary directory and performs the upgrade planning, including this extraction, with that copy. Now that a patched nx is the latest release, a defaultnx migraterun is unaffected whatever version the workspace has installed. The installed version only runs, and is only then exposed, when that hand-off is bypassed — see Remediation.Severity
Exploitable when the victim runs
nx migrateagainst a package the attacker controls, directly or through a trusted package'spackageGroup. The primary impact is a file write with attacker-controlled content and no path confinement; overwriting an auto-loaded file (a shell rc, a git hook, a CI script) escalates that write to code execution. There is no known evidence of exploitation in the wild.Affected & Patched Versions
nx>= 13.10.0, < 22.7.10;>= 23.0.0, < 23.2.122.7.10,23.2.1Every version in the ranges above is affected. The lower bound is 13.10.0, the first release where
nx migrateextracted a package's migrations file from its tarball; earlier versions resolved migrations without that extraction.Remediation
If you run
nx migratenormally, there is nothing to do. It resolves and runs the latest nx, which is patched, so your workspace's own nx version does not matter for this flaw.Upgrade only if you bypass that hand-off and run the workspace's nx instead — that is, if you set
NX_USE_LOCALorNX_MIGRATE_USE_LOCAL, pinNX_MIGRATE_CLI_VERSIONto an affected version, resume an existing run with--run-id, or run where the temporary install fails andnx migratefalls back to the local nx. In those cases upgrade to 22.7.10 (22.x line) or 23.2.1 (23.x line) or later:The fix is a drop-in — no configuration changes are required, and no legitimate
migrationsvalue is affected (real packages reference./migrations.jsonor another path within their own directory, all of which remain valid). Either way, do not runnx migrateagainst packages, orpackageGroupmembers, that you do not trust.Details
While planning an upgrade,
nx migrateextracts each target package's migrations file to a destination built by joining the package's ownnx-migrations.migrationsvalue onto a temporary directory. That value is read from the manifest without validation, and it is handled asymmetrically: the name Nx matches against the archive entries is normalized (so its..segments collapse), while the destination path it writes to is a raw join that keeps the..segments and resolves outside the temporary directory. Because the attacker controls the tarball, they name their entry to equal the normalized form; the match then succeeds and the bytes are written to the un-normalized, escaping destination. The normalization is not a defence — it only dictates what the attacker must name their entry.The same value also seeds the directory used for prompt-file extraction, which has the same shape, so both writes are steerable from the one field.
Two distinct primitives fall out of this:
migrationsat an existing file empties that file even when no tar entry matches — no crafted archive required.Credits
Severity
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:L/VI:H/VA:L/SC:N/SI:N/SA:NReferences
This data is provided by the GitHub Advisory Database (CC-BY 4.0).
Release Notes
nrwl/nx (nx)
v23.2.1Compare Source
23.2.1 (2026-09-09)
🚀 Features
🩹 Fixes
❤️ Thank You
Configuration
📅 Schedule: (UTC)
🚦 Automerge: Enabled.
♻ Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.