{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/nango/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nango:nango:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-9317"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Nango (\u003c 0.71.6)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","remote-code-execution","nango"],"_cs_type":"advisory","_cs_vendors":["Nango"],"content_html":"\u003cp\u003eNango versions prior to 0.71.6 are vulnerable to an authentication bypass in the runner tRPC server. An unauthenticated attacker with network access to the runner service can invoke the exposed 'start' procedure without providing the required RUNNER_SECRET_KEY. This flaw allows the execution of arbitrary JavaScript code within the context of the runner process, leading to remote code execution (RCE). The vulnerability stems from a failure to enforce authentication controls on specific internal tRPC procedures, making it a critical risk for deployments where the runner is reachable by untrusted network entities. Defenders must upgrade to version 0.71.6 or later to enforce proper credential validation.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker performs network reconnaissance to identify reachable runner ports associated with Nango deployments.\u003c/li\u003e\n\u003cli\u003eAttacker establishes a network connection to the target tRPC runner server port.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious tRPC request targeting the 'start' procedure.\u003c/li\u003e\n\u003cli\u003eAttacker omits or provides an invalid RUNNER_SECRET_KEY in the request payload.\u003c/li\u003e\n\u003cli\u003eThe Nango runner server fails to validate the request, incorrectly assuming authorization.\u003c/li\u003e\n\u003cli\u003eThe 'start' procedure processes the request and executes the embedded malicious JavaScript code.\u003c/li\u003e\n\u003cli\u003eAttacker achieves remote code execution within the runner process context.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to execute arbitrary JavaScript code on the Nango runner service. This can lead to full system compromise, unauthorized data access, and potential lateral movement within the network infrastructure where the runner is hosted.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Nango to version 0.71.6 or later immediately to patch CVE-2026-9317.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the Nango runner tRPC server port to authorized management subnets only.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering and monitoring to detect suspicious network activity originating from the Nango runner process.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-04T19:26:55Z","date_published":"2026-09-04T19:26:55Z","id":"https://feed.craftedsignal.io/briefs/2026-09-nango-auth-bypass/","summary":"Nango versions prior to 0.71.6 contain an authentication bypass vulnerability allowing unauthenticated attackers to achieve remote code execution via the tRPC runner server.","title":"Authentication Bypass in Nango Runner tRPC Server","url":"https://feed.craftedsignal.io/briefs/2026-09-nango-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Nango","version":"https://jsonfeed.org/version/1.1"}