Missing Authentication Vulnerability in Nango Runner tRPC Server
CVE-2026-9317

9.2CRITICAL

Key Information:

Vendor

Nangohq

Status
Vendor
CVE Published:
4 September 2026

What is CVE-2026-9317?

The Nango platform prior to version 0.71.6 is susceptible to a missing authentication vulnerability within its runner tRPC server. This flaw allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without requiring any credentials. Attackers who have network access to the runner port can exploit this vulnerability by sending requests to the start procedure, circumventing the unenforced RUNNER_SECRET_KEY environment variable. Consequently, this can lead to remote code execution within the runner process, posing a significant threat to the integrity and confidentiality of applications utilizing Nango.

Affected Version(s)

nango 0 < 0.71.6

References

CVSS V4

Score:
9.2
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Katriel Moses
VulnCheck
.