rootpwn

high · CVSS v3 7.1 · CVSS v4 7.1

CVE-2026-92804

Nango 0.70.4 does not validate user‑supplied configuration values that are interpolated into provider token and proxy URL templates. An auth

Overview

Nango 0.70.4 does not validate user‑supplied configuration values that are interpolated into provider token and proxy URL templates. An authenticated attacker can inject malicious values to force the server to send requests to internal or cloud metadata endpoints, potentially leaking provider credentials.

Description

Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.

Impact

Authenticated users can cause the Nango server to reach internal network addresses or cloud metadata services, exposing sensitive provider credentials. This leads to confidentiality loss of credential data and could enable further lateral movement or privilege escalation.

Remediation

['Upgrade to the latest Nango release (≥\u202f0.70.5) where input validation for template values has been added.', 'If an upgrade is not immediately possible, restrict the Nango service’s outbound network access to only approved endpoints and block connections to internal IP ranges and cloud metadata URLs.', 'Implement strict input validation or sanitization for all configuration fields that are used in URL or token templates.', 'Apply least‑privilege access controls so that only trusted users can modify provider configurations.']

Risk context

High severity (CVSS 7.1). No EPSS data available. The vulnerability can be exploited by authenticated users, making it a significant risk for environments where Nango is exposed to privileged personnel.

Affected products

  • Nango 0.70.4

Scores

Severity
high
CVSS v2
7.5
CVSS v3
7.1
CVSS v4
7.1
EPSS

configuration template-injection credential-exfiltration internal-attack Nango high

← All CVEs