Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. trigger.dev
  4. ›
  5. GHSA-q567-cr4x-96w4

GHSA-q567-cr4x-96w4: Trigger.dev: Blind SSRF via alert-channel webhook

October 2, 2026

A WEBHOOK alert channel stores a user-supplied url. When an alert fires (deployment/run failure, error groups), the webapp server (alertsWorker -> DeliverAlertService) POSTs the HMAC-signed alert payload to that URL via fetch(webhook.url, ...). The URL is never validated against a host allowlist or private-IP/metadata blocklist (a repo-wide search for 169.254, isPrivate, isLoopback, net.isIP, ssrf returns ZERO hits), and the API route’s URL field is just z.string().optional() (no syntax check at all). So an authenticated tenant can point the webhook at internal infrastructure or 169.254.169.254 and the multi-tenant server fetches it.

References

  • github.com/advisories/GHSA-q567-cr4x-96w4
  • github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254
  • github.com/triggerdotdev/trigger.dev/pull/4199
  • github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2
  • github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-q567-cr4x-96w4

Code Behaviors & Features

Detect and mitigate GHSA-q567-cr4x-96w4 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.5.2

Fixed versions

  • 4.5.2

Solution

Upgrade to version 4.5.2 or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

npm/trigger.dev/GHSA-q567-cr4x-96w4.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 03 Oct 2026 12:17:12 +0000.