PT-2026-86222 · Nango · Nango

·

CVE-2026-9317

·

Published

2026-09-04

·

Updated

2026-09-09

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Nango versions prior to 0.71.6
Description The runner tRPC server contains a missing authentication flaw that allows unauthenticated attackers with network access to the runner port to execute arbitrary JavaScript code. This is achieved by invoking the exposed start procedure without credentials, which bypasses the unenforced RUNNER SECRET KEY environment variable, leading to remote code execution within the runner process.
Recommendations Update to version 0.71.6 and set the NANGO INTERNAL AUTH REQUIRED environment variable to true.

Fix

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-9317

Affected Products

Nango