Answer in brief
CVE-2026-54753 records a Medium severity (CVSS 5.9) command injection vulnerability in `nx graph` dev server permissive CORS policy. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Answer in brief
CVE-2026-54753 records a Medium severity (CVSS 5.9) command injection vulnerability in `nx graph` dev server permissive CORS policy. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
Update nx to 22.7.2; nx to 23.0.0-beta.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCommand Injection describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-54753 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| nxnpm | >=17.0.4,<22.7.2 | 22.7.2 |
| nxnpm | >=23.0.0-beta.0,<23.0.0-beta.2 | 23.0.0-beta.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-54753 records a Medium severity (CVSS 5.9) command injection vulnerability in `nx graph` dev server permissive CORS policy. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for nx, nx.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL GuardUpdate nx to 22.7.2; nx to 23.0.0-beta.2 if you use the affected versions. Test the change in a non-production environment first.
Local check
hol-guard supply-chain scanCommand Injection describes the vulnerability class recorded for this advisory. The current record does not mark CVE-2026-54753 as known exploited; continue to monitor the source for status changes. The feed includes package mappings that can be checked against lockfiles and deployed manifests.
| Package | Affected range | Fixed version |
|---|---|---|
| nxnpm | >=17.0.4,<22.7.2 | 22.7.2 |
| nxnpm | >=23.0.0-beta.0,<23.0.0-beta.2 | 23.0.0-beta.2 |
Fixed versions are reported by the source feed; confirm compatibility before updating.
Reported by GitHub Security Advisories (ghsa).
CVE-2026-54753 records a Medium severity (CVSS 5.9) command injection vulnerability in `nx graph` dev server permissive CORS policy. The source record does not mark it as known exploited. 2 affected packages are mapped in the feed.
The source record does not mark it as known exploited.
Check lockfiles and deployed manifests for nx, nx.
HOL Guard can help your team review package activity against supported protection paths.
Explore HOL Guard## Summary The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's configured help command. The practical impact is typically **cross-origin information disclosure**, but can be arbitrary command injection in rare cases. ## Severity Exploitation requires the developer to be running `nx graph` and to visit an attacker page. Any execution beyond benign help commands also requires a malicious target to already be present in the workspace (see Details). ## Affected & Patched Versions Package: `nx` (npm). - **Affected:** `>= 17.0.4, < 22.7.2` and `>= 23.0.0-beta.0, < 23.0.0-beta.2` - **Patched:** `22.7.2`+ (backport) and `23.0.0` (first in `23.0.0-beta.2`) The wildcard CORS header was introduced in `17.0.4`; the `/help` execution endpoint in `19.4.0`. **The `21.x` line is not patched** — `21.x` users should upgrade to `22.7.2` or later. ## Details `nx graph` starts a local server (default `http://127.0.0.1:4211`). Before the fix, its request handler set a wildcard CORS header on every response: ```ts res.setHeader('Access-Control-Allow-Origin', '*'); ``` The `/help` endpoint runs a target's configured command: ```ts const command = target.metadata?.help?.command; return execSync(command, { cwd: target.options?.cwd ?? workspaceRoot }).toString(); ``` A `GET /help` is a CORS "simple request", so a malicious page could `fetch()` it with no preflight, and the wildcard header let the page read the result. This exposes the project graph (project names, file paths, dependencies, build configuration) and the output of any configured help command. The command is not attacker-controlled through the request — it comes from the workspace's project configuration, and first-party plugins (jest, vite, cypress) populate it with benign, read-only help commands. For `/help` to run anything malicious, a target carrying a malicious `help.command` must already exist in the project graph, which can only be introduced by **installing a malicious package** or by **altering the workspace's own code/configuration** — both of which already grant code execution independent of this flaw. The fix ([#35494](https://github.com/nrwl/nx/pull/35494)) removes the header; the browser's same-origin policy then blocks cross-origin reads. ## References - Fix: [nrwl/nx#35494](https://github.com/nrwl/nx/pull/35494) - Introduced: [nrwl/nx#20744](https://github.com/nrwl/nx/pull/20744) (CORS), [nrwl/nx#26629](https://github.com/nrwl/nx/pull/26629) (`/help`) ## Credits Thanks to Nozomu Sasaki (Paul) ([@morimori-dev](https://github.com/morimori-dev)) for finding and responsibly reporting this issue.
## Summary The local HTTP server started by `nx graph` sent `Access-Control-Allow-Origin: *` on every response, letting any website a developer visited read the server's responses cross-origin — including the full project graph and the output of the `/help` endpoint, which runs a target's configured help command. The practical impact is typically **cross-origin information disclosure**, but can be arbitrary command injection in rare cases. ## Severity Exploitation requires the developer to be running `nx graph` and to visit an attacker page. Any execution beyond benign help commands also requires a malicious target to already be present in the workspace (see Details). ## Affected & Patched Versions Package: `nx` (npm). - **Affected:** `>= 17.0.4, < 22.7.2` and `>= 23.0.0-beta.0, < 23.0.0-beta.2` - **Patched:** `22.7.2`+ (backport) and `23.0.0` (first in `23.0.0-beta.2`) The wildcard CORS header was introduced in `17.0.4`; the `/help` execution endpoint in `19.4.0`. **The `21.x` line is not patched** — `21.x` users should upgrade to `22.7.2` or later. ## Details `nx graph` starts a local server (default `http://127.0.0.1:4211`). Before the fix, its request handler set a wildcard CORS header on every response: ```ts res.setHeader('Access-Control-Allow-Origin', '*'); ``` The `/help` endpoint runs a target's configured command: ```ts const command = target.metadata?.help?.command; return execSync(command, { cwd: target.options?.cwd ?? workspaceRoot }).toString(); ``` A `GET /help` is a CORS "simple request", so a malicious page could `fetch()` it with no preflight, and the wildcard header let the page read the result. This exposes the project graph (project names, file paths, dependencies, build configuration) and the output of any configured help command. The command is not attacker-controlled through the request — it comes from the workspace's project configuration, and first-party plugins (jest, vite, cypress) populate it with benign, read-only help commands. For `/help` to run anything malicious, a target carrying a malicious `help.command` must already exist in the project graph, which can only be introduced by **installing a malicious package** or by **altering the workspace's own code/configuration** — both of which already grant code execution independent of this flaw. The fix ([#35494](https://github.com/nrwl/nx/pull/35494)) removes the header; the browser's same-origin policy then blocks cross-origin reads. ## References - Fix: [nrwl/nx#35494](https://github.com/nrwl/nx/pull/35494) - Introduced: [nrwl/nx#20744](https://github.com/nrwl/nx/pull/20744) (CORS), [nrwl/nx#26629](https://github.com/nrwl/nx/pull/26629) (`/help`) ## Credits Thanks to Nozomu Sasaki (Paul) ([@morimori-dev](https://github.com/morimori-dev)) for finding and responsibly reporting this issue.