ADVISORY

HIGH: nx — Nx: Zip-Slip in the self-hosted remote cache

Summary The Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory…

Source nxPublished 9d ago · Aug 6, 2026Posted on Threads

What we hold

Package
nx
Ecosystem
npm
Severity
HIGH
ID
CVE-2026-71476

Summary The Nx self-hosted HTTP remote cache extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory…

Learning about advisories like this one the day they are published is a separate problem from reading them here. Dependabot alerts, the GitHub Advisory Database API, OSV.dev and npm audit, compared against live responses: how to get an alert when a dependency has a new security advisory.