GHSA-gg6r-gp4c-89hp: Trigger.dev: V1 coordinator default-secret unauth Socket.IO
TL;DR
The /coordinator Socket.IO namespace mounts on every webapp boot and authenticates with a default secret (“coordinator-secret”) baked into source. The override variable isn’t documented in the self-host docs, .env.example, or helm values, so any operator who didn’t read source ships with the default. Once connected, READY_FOR_EXECUTION returns the run’s decrypted env vars. Anyone who can reach a default-config self-hosted webapp can pull production secrets out of any run whose internal id they can find.
Vulnerabilities
This attack is made possible by 3 vulnerabilities in Trigger.dev:
References
- github.com/advisories/GHSA-gg6r-gp4c-89hp
- github.com/triggerdotdev/trigger.dev/commit/5ba8557a51533be05f04245b03e1ca975cd57eff
- github.com/triggerdotdev/trigger.dev/pull/4236
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.4
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-gg6r-gp4c-89hp
Code Behaviors & Features
Detect and mitigate GHSA-gg6r-gp4c-89hp with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →