CVE-2026-104859: @nx/docker: OS command injection in the @nx/docker release pipeline
The @nx/docker release pipeline builds its docker invocations as shell command strings, interpolating release.docker.repositoryName and registryUrl from Nx configuration into them. Because those strings are handed to /bin/sh -c, a crafted repository or registry name executes as a command during nx release version and nx release publish. Anyone running a Docker release against a repository whose Nx configuration they do not control — or whose configuration a pull request has changed — executes the injected command with the privileges of the release job, which in CI typically holds registry credentials and cloud tokens.
References
- github.com/advisories/GHSA-6vc5-vf29-ffr2
- github.com/nrwl/nx/commit/6d60eed061f050e0d5af509a1f5a07c707f09865
- github.com/nrwl/nx/commit/b587441fd8da28c5db37edb0826554e0060dc81b
- github.com/nrwl/nx/pull/36505
- github.com/nrwl/nx/security/advisories/GHSA-6vc5-vf29-ffr2
- nvd.nist.gov/vuln/detail/CVE-2026-104859
Code Behaviors & Features
Detect and mitigate CVE-2026-104859 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →