THREAT OPS › Threat News › [GHSA] GHSA-vp3h-ghgh-jr7g (high) — Nx: Zip-Slip in the self-hosted remote cache
[GHSA] GHSA-vp3h-ghgh-jr7g (high) — Nx: Zip-Slip in the self-hosted remote cache
GHSA-vp3h-ghgh-jr7g Severity: high CVE: CVE-2026-71476
Nx: Zip-Slip in the self-hosted remote cache
## Summary
The Nx **self-hosted HTTP remote cache** extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on
Indicators of compromise
- CVE-2026-71476cve
- CVE-2025-36852cve
- https://nx.dev/docs/reference/deprecated/self-hosted-cache-packagesurl
Original source: https://github.com/advisories/GHSA-vp3h-ghgh-jr7g