Security: triggerdotdev/trigger.dev
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Cross-tenant deployment hijack: createDeploymentBackgroundWorkerV4 resolves a WorkerDeployment by friendlyId alone (no env/project/org scope) -> an attacker with only their own env API key re-points any other tenants in-progress deployment at a worker in the attackers environmentGHSA-2gvw-9968-v578 published
Jul 21, 2026 by carderneHigh -
Cross-organization schedule delete/disable: DeleteTaskScheduleService & SetActiveOnTaskScheduleService check membership on the callers own project then resolve the schedule by friendlyId with no projectId scope -> any org member destroys any other orgs IMPERATIVE cron schedulesGHSA-h4pj-26m5-j4r3 published
Jul 21, 2026 by carderneHigh -
Cross-environment deployment cancel: a lower-trust env key (dev/preview/CI) cancels another environment’s (e.g. production) deployments — DeploymentService.getDeployment scopes by projectId only, not environmentIdGHSA-4672-hwv6-gq62 published
Jul 21, 2026 by carderneModerate -
Prototype pollution via run metadata operations → process-wide cross-tenant DoS (CWE-1321)GHSA-p28v-f755-9qrg published
Jul 21, 2026 by carderneHigh -
SSRF via unvalidated alert-channel webhook URLGHSA-2wgf-7gx2-hcpw published
Jul 9, 2026 by carderneModerate -
Cross-tenant SQL injection in the TSQL query compiler (POST /api/v1/query) via unsanitized window-function nameGHSA-9q4r-4842-93vw published
Jul 21, 2026 by carderneHigh -
Overly broad realtime session credentials allow cross-session stream modification and deletionGHSA-cpx8-cffg-mp4w published
Jul 21, 2026 by carderneHigh -
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in triggerdotdev/trigger.devGHSA-gx7f-q62h-9fxp published
Jul 9, 2026 by carderneHigh -
GitHub App installation-link takeover via missing installation-ownership verificationGHSA-9rx3-j5hm-5f27 published
Sep 14, 2026 by carderneHigh -
Run replay injects a task run into an attacker-chosen environment (cross-tenant write)GHSA-qxpp-qjg8-x4jv published
Jul 9, 2026 by carderneHigh