CVE-2025-36852 is a critical vulnerability affecting remote cache extensions for common build systems utilizing bucket-based object storage (e.g., Amazon S3, Google Cloud Storage). It allows contributors with pull request privileges to inject compromised artifacts into trusted production environments by exploiting a "first-to-cache wins" design flaw. This bypasses traditional security measures as poisoning occurs during artifact construction. With a CVSS score of 9.4 (Critical), the vulnerability has a network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. There is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Niklas Portmann | Azure Based Remote Cache Plugin For Nx | 0CNA affecteddefault affected | |
| Niklas Portmann | Nx Remote Cache Utilities | 0CNA affecteddefault affected | |
| Niklas Portmann | Minio Based Remote Cache Plugin For Nx | 0CNA affecteddefault affected | |
| Nx | Azure Blob Remote Cache Plugin For Nx | 0CNA affecteddefault affected | |
| Nx | GCS Remote Cache Plugin For Nx | 0CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:Y/R:U/V:C/RE:M/U:Red
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.