GHSA-q567-cr4x-96w4: Trigger.dev: Blind SSRF via alert-channel webhook
A WEBHOOK alert channel stores a user-supplied url. When an alert fires (deployment/run failure, error groups), the webapp server (alertsWorker -> DeliverAlertService) POSTs the HMAC-signed alert payload to that URL via fetch(webhook.url, ...). The URL is never validated against a host allowlist or private-IP/metadata blocklist (a repo-wide search for 169.254, isPrivate, isLoopback, net.isIP, ssrf returns ZERO hits), and the API route’s URL field is just z.string().optional() (no syntax check at all). So an authenticated tenant can point the webhook at internal infrastructure or 169.254.169.254 and the multi-tenant server fetches it.
References
- github.com/advisories/GHSA-q567-cr4x-96w4
- github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254
- github.com/triggerdotdev/trigger.dev/pull/4199
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-q567-cr4x-96w4
Code Behaviors & Features
Detect and mitigate GHSA-q567-cr4x-96w4 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →