GHSA-4672-hwv6-gq62: Trigger.dev: Cross-environment deployment cancel
Trigger.dev isolates each project into multiple environments (dev, staging, prod, and per-PR preview branches), each with its own secret API key — the environment is a trust boundary (a dev/preview/CI key is lower-trust than a prod key). Most API routes enforce this by scoping resource lookups to the authenticated key’s environment (where: { friendlyId, runtimeEnvironmentId: auth.environment.id }).
The deployment cancel path does not. DeploymentService.getDeployment() scopes the lookup by projectId only — never environmentId — so a secret key for any environment in a project can cancel a deployment belonging to any other environment of the same project, including production. The deployment GET route, by contrast, is env-scoped — so the same key that is 404’d when trying to read a prod deployment can nonetheless cancel it. That asymmetry is the bug.
References
- github.com/advisories/GHSA-4672-hwv6-gq62
- github.com/triggerdotdev/trigger.dev/commit/6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0
- github.com/triggerdotdev/trigger.dev/pull/4316
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.6
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-4672-hwv6-gq62
Code Behaviors & Features
Detect and mitigate GHSA-4672-hwv6-gq62 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →