Impact
Nango versions through 0.70.4 accept user‑supplied configuration values that are interpolated into provider token and proxy URL templates without proper validation. This flaw allows an authenticated attacker to inject malicious configuration data, causing the Nango server to issue HTTP requests to arbitrary internal endpoints or cloud metadata services. The result can be the exfiltration of provider credentials or other sensitive data stored within the internal network.
Affected Systems
Nango by NangoHQ is affected for all releases up to and including version 0.70.4. All earlier versions are likewise vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity vulnerability. The EPSS score of < 1% suggests that widespread exploitation is currently unlikely, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires an authenticated user to supply a malicious configuration; an attacker would need legitimate access to the Nango application or to gain authentication credentials. Once authenticated, the attacker can craft configuration values to direct server‑side requests to arbitrary internal addresses, potentially leaking credentials or other sensitive data. The weakness aligns with CWE‑918, a Server‑Side Request Forgery vulnerability.
OpenCVE Enrichment