---
cve: "CVE-2026-104859"
severity: "HIGH"
cvss: 7.3
epss: ""
vendor: "nrwl"
kev: false
exploited: false
published: "2026-10-02 18:17:02"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-10-03T09:32:48+02:00"
---

# CVE-2026-104859

> 7.3 HIGH · 🧪 PoC

## Beschreibung

Nx is a monorepo solution for TypeScript and polyglot codebases. From 21.4.0 until 22.7.8 and from 23.0.0 until 23.1.1, the @nx/docker release pipeline builds docker tag, image lookup, and docker push invocations as shell command strings. The release.docker.repositoryName and registryUrl configuration values are interpolated into those strings and passed to /bin/sh -c, allowing shell syntax in untrusted Nx configuration to execute during nx release version or nx release publish. A pull request or repository configuration change can therefore execute commands with the release job's privileges and expose registry credentials or cloud tokens, and dry-run publishing does not prevent the vulnerable pre-check command from executing. This issue is fixed in versions 22.7.8 and 23.1.1.

## CNA-Record (Kanon, cvelistV5)

- CNA: **GitHub_M**
- State: PUBLISHED
- Stand: 2026-10-02 17:49:37
- CNA-CVSS: **7.3** (`CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N`)

## CVSS-Vektor

```
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |

## Patch verfügbar (OSV)

- f7afd77de568bc5f1edbd94e2c6b0707cdf52d68 (Commit)
- 8841f1cc5d4e3667777ef91b5bc956bc6882fb9d (Commit)

## Referenzen

- <https://github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2>
- <https://github.com/nrwl/nx/pull/36505>
- <https://github.com/nrwl/nx/commit/6d60eed061f050e0d5af509a1f5a07c707f09865>
- <https://github.com/nrwl/nx/commit/b587441fd8da28c5db37edb0826554e0060dc81b>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2026-104859) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
