GHSA-fj2x-mqqp-3v2w: Trigger.dev: Trigger CLI debug deployment logs expose resolved environment secret values
Affected version: trigger.dev 4.5.3 (4.5.6 was advertised by the CLI but was not tested).
A staging dry-run executed with trigger.dev deploy --env staging --dry-run --log-level debug. The debug output logged the complete build-worker options object. Its envVars property contained unredacted values for every resolved staging variable, including database connection strings and service credentials. The non-debug environment listing correctly hides values, so users can reasonably expect deployment logs not to print secrets.
Impact: anyone with access to a developer terminal transcript, CI debug log, captured agent/tool output, or support bundle can recover deployment secrets even though no deployment occurs.
Reproduction:
- Configure a Trigger.dev project with a secret environment variable.
- Run the command above with an authenticated profile.
- Inspect the
Starting buildWorkerdebug record. options.envVarscontains the plaintext value.
No real credential is included in this report. The observed customer credentials are being rotated separately.
Suggested remediation: never serialize envVars values in debug output; log names only or replace every value with a fixed marker. Add regression coverage for deploy, dry-run, and debug logging, and review adjacent debug records for resolved secrets.
References
- github.com/advisories/GHSA-fj2x-mqqp-3v2w
- github.com/triggerdotdev/trigger.dev/commit/878c15811aca8339a751aa0c2211012db7a47ce5
- github.com/triggerdotdev/trigger.dev/pull/4420
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.9
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-fj2x-mqqp-3v2w
Code Behaviors & Features
Detect and mitigate GHSA-fj2x-mqqp-3v2w with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →