THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-vp3h-ghgh-jr7g (high) — Nx: Zip-Slip in the self-hosted remote cache

[GHSA] GHSA-vp3h-ghgh-jr7g (high) — Nx: Zip-Slip in the self-hosted remote cache

highgithub_advisoriesPublished 2026-08-06

GHSA-vp3h-ghgh-jr7g Severity: high CVE: CVE-2026-71476

Nx: Zip-Slip in the self-hosted remote cache

## Summary

The Nx **self-hosted HTTP remote cache** extracts downloaded cache artifacts without constraining where files are written. A malicious — or on-path (MITM) — remote cache server can return a crafted tar archive whose entries escape the cache directory and write to arbitrary locations on

Indicators of compromise

Original source: https://github.com/advisories/GHSA-vp3h-ghgh-jr7g