CVE-2026-9317

    Dashboard / Vulnerabilities / CVE-2026-9317

    CVE-2026-9317

    Published: 4 Sept 2026Last Modified: 25 Sept 2026

    Summary: Nango < 0.71.6 Missing Authentication RCE via runner tRPC server

    Details: Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attackers with network access to the runner port can send requests to the unauthenticated start procedure, bypassing the unenforced RUNNER_SECRET_KEY environment variable, to achieve remote code execution within the runner process.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Affected versions

    managed-1.6.7-0.71.5-b14e3aa3e113fd0996a2484e6ba7befe3261ecc1
    managed-1.6.6-0.71.4-3b2c0410e3b8444d5eacb45817f74ee8d462711a
    managed-1.6.5-0.71.4-b6a11be5e83e48fc2f4758685ce2d6a12d817fad
    managed-1.6.4-0.71.3-3d6911d08f7a24b2b34dc70b38c4fc2ff043fbfc
    managed-1.6.3-0.71.2-d9783cb2211312d673184aff9974df9535972863
    managed-1.6.2-0.71.2-fad81b1da5b2495db013a2b6cd922049ed57da2c
    managed-1.6.1-0.71.2-6c4a526ed4928b2fb815f9933b502722230f50e6
    managed-1.6.0-0.71.0-b27d0d367c67d1bf61f11a01c5e57fd550778b05

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2026-9317 | CVE-DB