PT-2026-86222 · Nango · Nango
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Nango versions prior to 0.71.6
Description
The runner tRPC server contains a missing authentication flaw that allows unauthenticated attackers with network access to the runner port to execute arbitrary JavaScript code. This is achieved by invoking the exposed
start procedure without credentials, which bypasses the unenforced RUNNER SECRET KEY environment variable, leading to remote code execution within the runner process.Recommendations
Update to version 0.71.6 and set the
NANGO INTERNAL AUTH REQUIRED environment variable to true.Fix
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Nango