{"type":"bundle","id":"bundle--aa2d1876-2c18-5a4b-a032-4d057a135cf2","objects":[{"type":"campaign","spec_version":"2.1","id":"campaign--eb80ebda-82b2-54c2-9cc3-19aee0b1d7fd","created":"2026-09-20T18:57:45.490Z","modified":"2026-09-20T18:57:45.490Z","name":"Nango runner missing auth lets remote callers run code","description":"Nango before 0.71.6 is missing authentication on the runner tRPC server, allowing anyone who can reach the runner to execute code. Fixed in 0.71.6.","aliases":["CVE-2026-9317","Nango runner tRPC RCE"],"first_seen":"2026-09-04T00:00:00.000Z","last_seen":"2026-09-04T12:00:00.000Z","objective":"Defensive public threat-intelligence record; see limitations and source references.","external_references":[{"source_name":"VulnCheck Nango advisory","url":"https://www.vulncheck.com/advisories/nango-missing-authentication-rce-via-runner-trpc-server"},{"source_name":"NVD CVE-2026-9317","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-9317"},{"source_name":"HOL Guard operator write-up","url":"https://hol.org/blog/cve-2026-9317-nango-runner-trpc-missing-auth-rce"},{"source_name":"Nango v0.71.6 release","url":"https://github.com/NangoHQ/nango/releases/tag/v0.71.6"}]}]}