Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configura…
High CVSS 7.1
Summary
Nango through 0.70.4 fails to validate caller-supplied connection configuration values interpolated into provider token and proxy URL templates. Authenticated attackers can supply malicious configuration values to direct server requests at internal addresses or cloud metadata endpoints, potentially exfiltrating provider credentials.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Sources
- NVD DATABASE
Original Links
- https://github.com/NangoHQ/nango
- https://github.com/NangoHQ/nango/blob/v0.70.4/packages/shared/lib/utils/utils.ts
- https://github.com/NangoHQ/nango/security/advisories/GHSA-hgjm-c252-ccxx
- https://www.vulncheck.com/advisories/nango-through-0.70.4-server-side-request-forgery-via-configuration
- https://github.com/NangoHQ/nango/security/advisories/GHSA-hgjm-c252-ccxx
Timeline
- nvd_ingest NVD