Security: triggerdotdev/trigger.dev
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Server-side request forgery via unvalidated webhook alert-channel URLGHSA-xxv7-2vv3-h682 published
Jul 9, 2026 by carderneHigh -
Cross-project deployment worker registration can modify another project's deployment stateGHSA-j6vv-pq9h-f4wj published
Jul 9, 2026 by carderneCritical -
Cross-tenant task-run read via tags where-clause injection in realtime APIGHSA-p6j2-2fjh-vc8v published
Jul 21, 2026 by carderneHigh -
Cross-tenant object read/write via path traversal in packet presign APIGHSA-m3mf-37q7-8928 published
Jul 9, 2026 by carderneHigh -
Supervisor workload API lacks cross-tenant authenticationGHSA-jc26-22qp-cgqj published
Sep 14, 2026 by carderneHigh -
Unauthenticated Realtime Stream Data Injection via Run FriendlyIdGHSA-59h8-w5q6-mfmp published
Jul 21, 2026 by carderneModerate -
Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure CompromiseGHSA-pqxw-g93w-hj9x published
Jul 21, 2026 by carderneHigh -
V1 coordinator default-secret unauth Socket.IOGHSA-gg6r-gp4c-89hp published
Jul 20, 2026 by carderneModerate -
Cross-tenant payload poisoning via packet write + replayGHSA-jx48-qfwm-xq67 published
Jul 9, 2026 by carderneModerate -
Cross-tenant object store read and write via URL path traversalGHSA-888c-px7m-736v published
Jul 9, 2026 by carderneHigh