---
id: CVE-2026-92804
title: >-
  Nango through 0.70.4 fails to validate caller-supplied connection
  configuration values interpolated into provider token and proxy URL templates
summary: >-
  Nango through 0.70.4 fails to validate caller-supplied connection
  configuration values interpolated into provider token and proxy URL templates.
  Authenticated attackers can supply malicious configuration values to direct
  server requests …
severity: high
cvss: 7.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N'
cwe:
  - CWE-918
vendor: NangoHQ
product: Nango
affected:
  - Nango <= 0.70.4
published: '2026-09-16'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T20:43:58.793'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92804'
references:
  - url: 'https://github.com/NangoHQ/nango'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/NangoHQ/nango/blob/v0.70.4/packages/shared/lib/utils/utils.ts
    label: disclosure@vulncheck.com
  - url: 'https://github.com/NangoHQ/nango/security/advisories/GHSA-hgjm-c252-ccxx'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/nango-through-0.70.4-server-side-request-forgery-via-configuration
    label: disclosure@vulncheck.com
  - url: 'https://github.com/NangoHQ/nango/security/advisories/GHSA-hgjm-c252-ccxx'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
epss: 0.00277
epssPercentile: 0.2037
ingestedAt: '2026-09-16T21:05:36.884Z'
---

## Overview

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
