Security: triggerdotdev/trigger.dev
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Slack OAuth state is not session-bound, enabling integration CSRFGHSA-hc5h-gqhc-4h79 published
Aug 20, 2026 by carderneModerate -
Trigger CLI debug deployment logs expose resolved environment secret valuesGHSA-fj2x-mqqp-3v2w published
Jul 31, 2026 by carderneModerate -
Webhook SSRF fix bypass via non-global 198.18.0.0/15 benchmarking rangeGHSA-fhh4-xvj5-m7pq published
Aug 7, 2026 by carderneModerate -
Delegated user-actor token capability checks are bypassed by the legacy alert-channel API.GHSA-wpjq-q67r-pg6m published
Aug 20, 2026 by carderneModerate -
Blind SSRF via alert-channel webhook: the webapp server POSTs HMAC-signed alert payloads to a user-set URL with no host allowlist / private-IP block (url validated only as z.string().optional())GHSA-q567-cr4x-96w4 published
Jul 9, 2026 by carderneModerate -
Cross-tenant deployment hijack: createDeploymentBackgroundWorkerV4 resolves a WorkerDeployment by friendlyId alone (no env/project/org scope) -> an attacker with only their own env API key re-points any other tenants in-progress deployment at a worker in the attackers environmentGHSA-2gvw-9968-v578 published
Jul 21, 2026 by carderneHigh -
Cross-organization schedule delete/disable: DeleteTaskScheduleService & SetActiveOnTaskScheduleService check membership on the callers own project then resolve the schedule by friendlyId with no projectId scope -> any org member destroys any other orgs IMPERATIVE cron schedulesGHSA-h4pj-26m5-j4r3 published
Jul 21, 2026 by carderneHigh -
Cross-environment deployment cancel: a lower-trust env key (dev/preview/CI) cancels another environment’s (e.g. production) deployments — DeploymentService.getDeployment scopes by projectId only, not environmentIdGHSA-4672-hwv6-gq62 published
Jul 21, 2026 by carderneModerate -
Prototype pollution via run metadata operations → process-wide cross-tenant DoS (CWE-1321)GHSA-p28v-f755-9qrg published
Jul 21, 2026 by carderneHigh -
SSRF via unvalidated alert-channel webhook URLGHSA-2wgf-7gx2-hcpw published
Jul 9, 2026 by carderneModerate