SCA: security update for nx (GHSA-vp3h-ghgh-jr7g)

high Tenable Cloud Security Plugin ID 445778

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Nx is a monorepo solution for TypeScript and polyglot codebases. From version 20.8.0 until 22.7.7 and
23.0.2, the Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining
where files are written. A malicious or on-path (MITM) remote cache server can return a crafted tar
archive whose entries escape the cache directory and write to arbitrary locations on the machine running
Nx, which can be escalated to remote code execution. Nx's default local cache and Nx Cloud are not
affected; only workspaces configured to use a self-hosted remote cache are affected. This issue is fixed
in versions 22.7.7 and 23.0.2. (CVE-2026-71476)

Solution

Update the nx library and its related packages to version 22.7.7 or later.

See Also

https://github.com/advisories/GHSA-vp3h-ghgh-jr7g

Plugin Details

Severity: High

ID: 445778

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 8/7/2026

Updated: 8/7/2026

Risk Information

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Temporal Score: 5

Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS Score Source: CVE-2026-71476

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 8.7

Threat Score: 6.3

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 8/6/2026

Vulnerability Publication Date: 8/6/2026

Reference Information

CVE: CVE-2026-71476