Missing Authentication Vulnerability in Nango Runner tRPC Server
CVE-2026-9317
9.2CRITICAL
What is CVE-2026-9317?
The Nango platform prior to version 0.71.6 is susceptible to a missing authentication vulnerability within its runner tRPC server. This flaw allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without requiring any credentials. Attackers who have network access to the runner port can exploit this vulnerability by sending requests to the start procedure, circumventing the unenforced RUNNER_SECRET_KEY environment variable. Consequently, this can lead to remote code execution within the runner process, posing a significant threat to the integrity and confidentiality of applications utilizing Nango.
Affected Version(s)
nango 0 < 0.71.6
