critical

CVE

CVE-2026-104859, CVE-2026-104848, CVE-2026-104849, CVE-2026-105219

CWE

CWE-78, CWE-1321, CWE-1333

Affected Surface

  • Nx release pipelines running vulnerable `@nx/docker` versions and exposing registry, cloud, or signing credentials to CI jobs
  • Node.js services, build tools, and CI workers that instantiate vulnerable `tinypool` versions in the same process as attacker-triggerable prototype pollution
  • Apps or back-end conversion services that feed attacker-controlled `.docx` files into vulnerable `mammoth` builds on the main Node.js event loop

Welcome to Corgea’s weekly briefing. The briefing covers the most important security findings and research from the week.

This edition covers new reporting and disclosures published between Thursday, 2 October and Monday, 5 October 2026. The requested sweep across CISA KEV, NVD, Aikido, Wiz, Socket, Endor Labs, and broader web search did not surface a fresher package-registry compromise or Linux-focused zero day than the new npm disclosure cluster below.

Top Article

CVE-2026-104859: @nx/docker turned release configuration into /bin/sh -c

The strongest new package-security finding in this window is CVE-2026-104859 in @nx/docker. It is not a runtime bug in the application code that Nx builds. It is a release-pipeline boundary failure in the code that tags, locates, and pushes Docker images.

That distinction matters because the affected job usually runs with the exact secrets an attacker wants: container-registry credentials, cloud deployment tokens, and trusted builder access. In vulnerable versions, Nx constructed docker tag, docker images, and docker push as interpolated shell strings. Values from repositoryName, registryUrl, --dockerVersion, and NX_DOCKER_IMAGE_REF flowed in unescaped. The fixed code switches to execFile() and execFileSync() argv arrays, which is the difference between “Docker sees one bad argument” and “the shell executes a second command.”

The advisory also has one operational detail that is easy to miss: dry-run publishing still evaluated the vulnerable docker images --filter ... pre-check before respecting the dry-run flag. If you need the full code path, the new Corgea article breaks down the .docker-version handoff, the three shell boundaries, and the regression test that uses --dockerVersion='1.0.0; touch injected.txt'.

More news

Tinypool published two worker-thread RCE gadgets in consecutive fixes

CVE-2026-104848 and CVE-2026-104849 landed on 2 October and are best read together. Both affect the npm package tinypool, which many test runners, bundlers, and internal tooling stacks use to fan out work onto Node worker threads.

The first bug was fixed in 2.1.1. Tinypool previously merged worker options with a normal object:

this.options = { ...kDefaultOptions, ...options, filename, maxQueue: 0 }

That let a polluted Object.prototype.execArgv or Object.prototype.env become real worker options. In practice, that can turn an unrelated prototype-pollution bug elsewhere in the same process into attacker-controlled --import flags or NODE_OPTIONS for every new worker.

The follow-up bug fixed in 2.1.2 closed a second edge: pool.run(task, options) still trusted inherited filename on the caller-supplied options object. The patch moved more option handling behind prototype-less copies, including:

const { transferList, filename, name, signal, runtime, channel } =
  withNullPrototype(options)

This is not a “Tinypool causes prototype pollution” story. The package becomes dangerous after another bug has already polluted Object.prototype. For teams with Node build workers or long-lived back-end processes, that still makes Tinypool part of the exploit chain.

Mammoth.js fixed a tiny regex change with a real event-loop consequence

CVE-2026-105219 affects mammoth 1.3.0 through 1.12.2, the package many teams use to convert .docx files to HTML or Markdown. The vulnerable parser used these overlapping patterns for quoted style-map strings:

var stringPrefix = "'((?:\\\\.|[^'])*)";
{ name: "string", regex: new RegExp(stringPrefix + "'") }
{ name: "unterminated-string", regex: new RegExp(stringPrefix) }

An unterminated quoted string with lots of escape sequences could drive excessive backtracking and pin the Node.js event loop. The fix in 1.12.3 is only a one-line regex change:

var stringPrefix = "'((?:\\\\(?:.|$)|[^'\\\\])*)";

That small change is exactly the point. Attackers do not always need a big parser bug. If your document-conversion service handles untrusted uploads inline on the main event loop, a one-line regex mistake can still become application-level denial of service.

Other news

  • The requested CISA KEV sweep in this window produced fresh entries for Citrix NetScaler and a Zammad chain, but not a stronger package-manager or Linux developer-surface story than the npm items above.
  • The requested Aikido, Wiz, Socket, and Endor Labs page review did not surface a brand-new package compromise dated 2-5 October that beat the Nx, Tinypool, and Mammoth disclosures on timeliness or technical depth. The freshest strong package write-ups on those sites in this run were older carry-over stories such as Axios, MemTensor, and earlier Shai-Hulud follow-ons, which Corgea already covered or which fell outside the requested date window.
  • If you are triaging CI and build-tool exposure this week, start with @nx/docker and tinypool before the document-conversion edge cases. Both are more likely to sit on machines that already hold credentials an attacker can reuse.

From research to remediation

Check whether this pattern exists in your codebase

Turn this research into a remediation workflow. Scan dependencies and package manifests for similar supply-chain risk, then prioritize fixes with reachability context.

References