HIGH
nrwl
CVE published 2026-08-06
CVE-2026-71476
CVE-2026-71476 is a high-severity vulnerability affecting Nx, a monorepo solution for TypeScript and polyglot codebases. The vulnerability exists in the Nx self-hosted HTTP remote cache, allowing a malicious or on-path remote cache server to return a crafted tar archive that can write to arbitrary locations on the machine running Nx, potentially leading to remote code execution.