GHSA-pqxw-g93w-hj9x: Trigger.dev Self-Hosted Deployment: Default Secrets allow Unauthenticated Infrastructure Compromise
Self-hosted trigger.dev v4 instances deployed using the provided Docker Compose configuration with default secrets from hosting/docker/.env.example are vulnerable to a multi-stage unauthenticated attack chain leading to complete infrastructure compromise.
References
- github.com/advisories/GHSA-pqxw-g93w-hj9x
- github.com/triggerdotdev/trigger.dev/commit/6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0
- github.com/triggerdotdev/trigger.dev/pull/4316
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.6
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-pqxw-g93w-hj9x
Code Behaviors & Features
Detect and mitigate GHSA-pqxw-g93w-hj9x with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →