GHSA-qxpp-qjg8-x4jv: Trigger.dev: Run replay injects a task run into an attacker-chosen environment (cross-tenant write)
The dashboard replay action authorizes the source run (it must belong to the caller’s org), but the target environment for the replayed run is taken verbatim from the request body and is never checked for org or project membership. The environment lookup used by the replay path filters by id only. As a result, an authenticated user can replay one of their own runs into another organization’s or project’s environment, creating a task run there that consumes the victim tenant’s queue and compute and pollutes their run history.
References
- github.com/advisories/GHSA-qxpp-qjg8-x4jv
- github.com/triggerdotdev/trigger.dev/commit/34b1a181c2a1d33a53ebab88f84b05f81fea4254
- github.com/triggerdotdev/trigger.dev/pull/4199
- github.com/triggerdotdev/trigger.dev/releases/tag/v4.5.2
- github.com/triggerdotdev/trigger.dev/security/advisories/GHSA-qxpp-qjg8-x4jv
Code Behaviors & Features
Detect and mitigate GHSA-qxpp-qjg8-x4jv with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →