nx
npm3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting nxpage 1 of 1
- CVE-2025-10894CRITICALCVSS 9.6EG 9.62025-09-24
vulnerable: 20.9.0 ... 21.8.0 (8 versions)
Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file syst…
- CVE-2026-54753MEDIUMCVSS 5.9EG 5.9✓ Fixed in 23.0.0-beta.22026-06-26
Nx is a monorepo solution for TypeScript and polyglot codebases. From 17.0.4 until 22.7.2 and 23.0.0-beta.2, the local HTTP server started by nx graph sent Access-Control-Allow-Origin: * on every response, letting any website a developer v…
- CVE-2026-71476HIGHCVSS 8.7EG 8.7✓ Fixed in 23.0.22026-08-06
Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and 23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A maliciou…
Check whether nx is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for nx CVEs against the assets you own.
Start Free Scan →