Impact
A flaw in Nango versions prior to 0.71.6 allows an attacker to invoke the exposed start procedure on the runner tRPC server without authentication, enabling the execution of arbitrary JavaScript code within the runner process. The vulnerability bypasses the RUNNER_SECRET_KEY check, meaning that no credentials are required to trigger code execution.
Affected Systems
The affected product is Nango, distributed by NangoHQ. All releases before version 0.71.6 are vulnerable; upgrading to 0.71.6 or later removes the flaw.
Risk and Exploitability
The CVSS score of 9.2 classifies this as Critical. Although the EPSS score is not provided, the lack of authentication and the ability to execute code remotely make exploitation highly likely if the runner port is reachable from the network. This CVE is not listed in the CISA KEV catalog, but the vulnerability itself remains exploitable until patched. Attackers can compromise the runner environment, potentially affecting any services or data that the runner can access.
OpenCVE Enrichment