A high-severity vulnerability tracked as CVE-2026-71476 affects the Nx monorepo build system when it is configured to use a self-hosted HTTP remote cache. A malicious cache server, or an attacker positioned for man-in-the-middle access, can return a crafted tar archive containing path traversal entries such as .., absolute paths, or symlink and hardlink escapes, allowing files to be written outside the intended cache directory or workspace. The arbitrary file-write condition can lead to remote code execution, including by overwriting sensitive files such as SSH keys, Git hooks, or shell startup files. Nx said its default local cache and Nx Cloud are not affected.
The issue impacts Nx 20.8.0 through before 22.7.7 and 23.0.0 through before 23.0.2. Maintainers fixed the flaw by constraining tar extraction to the intended directory, limiting restore operations to declared task outputs within the workspace, blocking writes through symlinks, and rejecting outputs that resolve outside the workspace; they also converted malformed-input panic cases into explicit errors and corrected a separate bug that decoded cached exit codes from only two of four stored bytes. The remediation was shipped in 22.7.7 and 23.0.2, alongside expanded tests covering traversal, absolute-path handling, symlink and hardlink escapes, malformed artifacts, and exit-code round-tripping.

Trace attribution and downstream blast radius.
4 events from the most recent confirmed update back to the earliest known activity.
The CVE record states that security-advisories@github.com received CVE-2026-71476 on August 6, 2026. The vulnerability covers zip-slip/path traversal in Nx self-hosted HTTP remote cache affecting versions 20.8.0 through before 22.7.7 and 23.0.0 through before 23.0.2.
Nx published commits 2b20c2d and a828076 carrying the remote-cache zip-slip fix into release lines, including a cherry-pick into the 22.7.x branch. The commits addressed arbitrary file write and potential RCE risks from crafted tar archives returned by a malicious or MITM self-hosted cache server.
Nx authored commit ad29657 with the message "fix(core): prevent path traversal / zip-slip in self-hosted remote cache (#36116)." The patch contained extraction within the cache directory, limited restores to declared outputs, blocked symlink and hardlink escapes, and fixed malformed-input panic and exit-code parsing issues.
Nx opened pull request #36116 to address a path traversal/zip-slip issue in the self-hosted HTTP remote cache. The PR later became the vehicle for fixes that contained tar extraction, constrained restore behavior, and hardened error handling.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution and downstream blast radius, and whether this package or vendor reaches your builds.
5 references tracked. Mallory keeps watching after this page renders.
cvefeed.io
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourcegithub.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.