Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. trigger.dev
  4. ›
  5. GHSA-qxpp-qjg8-x4jv

GHSA-qxpp-qjg8-x4jv: Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)

October 2, 2026

The dashboard replay action authorizes the source run (it must belong to the caller’s org), but the target environment for the replayed run is taken verbatim from the request body and is never checked for org or project membership. The environment lookup used by the replay path filters by id only. As a result, an authenticated user can replay one of their own runs into another organization’s or project’s environment, creating a task run there that consumes the victim tenant’s queue and compute and pollutes their run history.

References

  • github.com/advisories/GHSA-qxpp-qjg8-x4jv
  • github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254
  • github.com/triggerdotdev/trigger.dev/pull/4199
  • github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2
  • github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jv

Code Behaviors & Features

Detect and mitigate GHSA-qxpp-qjg8-x4jv with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 4.5.2

Fixed versions

  • 4.5.2

Solution

Upgrade to version 4.5.2 or above.

Impact 7.1 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L

Learn more about CVSS

Weakness

  • CWE-639: Authorization Bypass Through User-Controlled Key

Source file

npm/trigger.dev/GHSA-qxpp-qjg8-x4jv.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 03 Oct 2026 12:16:58 +0000.