23.1.1
15 years ago
9 days ago
Known vulnerabilities in the nx package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
nx is a The core Nx plugin contains the core functionality of Nx like the project graph, nx commands and task orchestration. Affected versions of this package are vulnerable to Symlink Attack via the extraction process. An attacker can write arbitrary files to locations outside the intended directory by supplying a crafted tar archive with malicious entries. This can lead to remote code execution if the attacker is able to control the contents of the extracted files. How to fix Symlink Attack? Upgrade | >=20.8.0 <22.7.7>=23.0.0 <23.0.2>=23.1.0-beta.0 <23.1.0-beta.5 |
nx is a The core Nx plugin contains the core functionality of Nx like the project graph, nx commands and task orchestration. Affected versions of this package are vulnerable to Exposed Dangerous Method or Function via the local HTTP server's permissive CORS policy, which sends How to fix Exposed Dangerous Method or Function? Upgrade | >=17.0.4 <22.7.2>=23.0.0-beta.0 <23.0.0-beta.2 |