nango vulnerabilities
CVEs whose affected-version data names the nango package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-92804High· 7.1Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates
Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests …
▾ TwilightNangoHQ · NangoEPSS 0.28%via NVD
CVE-2026-9317High· 8.1Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials
Nango before 0.71.6 contains a missing authentication vulnerability in the runner tRPC server that allows unauthenticated attackers to execute arbitrary JavaScript code by invoking the exposed start procedure without credentials. Attacke…
▾ TwilightNangoHQ · nangoEPSS 0.68%via NVD