<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-08T21:26:33.696919+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/brew-nx-cve-2026-104854</id>
    <title>BREW-nx-CVE-2026-104854 — Nx daemon and plugin worker sockets are accessible to other local users</title>
    <updated>2026-10-08T21:26:33.700315+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Homebrew: nx</p>
<p>## Summary</p>
<p>Nx creates the Unix domain sockets for its daemon and its plugin workers in a shared temporary directory with default permissions, so any other user on the same machine can connect to them. The daemon accepts a `PROCESS_IN_BACKGROUND` request that names a module to load and invokes its default export, which turns socket access into code execution inside the daemon process. On a multi-user machine — a shared build server, a shared developer box, or a container running several accounts — one local user can execute code as another user running Nx.</p>
<p>## Severity</p>
<p>Exploitable by any other unprivileged local user on a shared host while a daemon or plugin worker is running, with no user interaction. There is no known evidence of exploitation in the wild.</p>
<p>## Affected &amp; Patched Versions</p>
<p>| Package | Vulnerable | Patched |
| --- | --- | --- |
| `nx` | `&gt;= 14.6.0, &lt; 22.7.9`; `&gt;= 23.0.0, &lt; 23.1.2` | `22.7.9`, `23.1.2` |</p>
<p>Every version in the ranges above is affected. The lower bound is 14.6.0, when the daemon request handler that turns socket access into code execution was added.</p>
<p>&gt; [!IMPORTANT]
&gt; Single-user machines are not exposed. The vulnerability requires another local account on the same host, so an ordinary laptop with one user account is unaffected — the exposure is shared CI runners, shared build and development servers, and containers or images that run more than one uid.
&gt;
&gt; Disabling the daemon is not sufficient on its own: the plugin worker sockets used by plu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/brew-nx-cve-2026-104854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-382425</id>
    <title>EUVD-2026-382425</title>
    <updated>2026-10-08T21:26:33.700433+00:00</updated>
    <content>EUVD-2026-382425</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-382425"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2026-104854</id>
    <title>fkie_cve-2026-104854</title>
    <updated>2026-10-08T21:26:33.700463+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Nx is a monorepo solution for TypeScript and polyglot codebases. From 14.6.0 until 22.7.9 and 23.1.2, Nx creates Unix domain sockets for its daemon and isolated plugin workers in shared temporary locations without owner-only directory and socket permissions. Another unprivileged local account on a shared build server, developer host, or multi-user container can discover and connect to a running socket because the transport performs no authentication and relies on filesystem containment. The daemon's PROCESS_IN_BACKGROUND request accepts a module path and invokes its default export, allowing a caller that controls a file to execute code as the account running Nx; other handlers can expose workspace file contents, project graphs, and task hashes. Disabling the daemon alone does not remove the vulnerable plugin-worker sockets, while single-user machines without another local account are not exposed. This issue is fixed in versions 22.7.9 and 23.1.2.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2026-104854"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-w3vv-58gj-gw77</id>
    <title>GHSA-w3vv-58gj-gw77 — Nx daemon and plugin worker sockets are accessible to other local users</title>
    <updated>2026-10-08T21:26:33.700555+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: nx</p>
<p>## Summary</p>
<p>Nx creates the Unix domain sockets for its daemon and its plugin workers in a shared temporary directory with default permissions, so any other user on the same machine can connect to them. The daemon accepts a `PROCESS_IN_BACKGROUND` request that names a module to load and invokes its default export, which turns socket access into code execution inside the daemon process. On a multi-user machine — a shared build server, a shared developer box, or a container running several accounts — one local user can execute code as another user running Nx.</p>
<p>## Severity</p>
<p>Exploitable by any other unprivileged local user on a shared host while a daemon or plugin worker is running, with no user interaction. There is no known evidence of exploitation in the wild.</p>
<p>## Affected &amp; Patched Versions</p>
<p>| Package | Vulnerable | Patched |
| --- | --- | --- |
| `nx` | `&gt;= 14.6.0, &lt; 22.7.9`; `&gt;= 23.0.0, &lt; 23.1.2` | `22.7.9`, `23.1.2` |</p>
<p>Every version in the ranges above is affected. The lower bound is 14.6.0, when the daemon request handler that turns socket access into code execution was added.</p>
<p>&gt; [!IMPORTANT]
&gt; Single-user machines are not exposed. The vulnerability requires another local account on the same host, so an ordinary laptop with one user account is unaffected — the exposure is shared CI runners, shared build and development servers, and containers or images that run more than one uid.
&gt;
&gt; Disabling the daemon is not sufficient on its own: the plugin worker sockets used by plu…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-w3vv-58gj-gw77"/>
  </entry>
</feed>
