GHSA-4672-HWV6-GQ62: Cross-environment deployment cancellation in Trigger.dev
Vulnerability ID: GHSA-4672-HWV6-GQ62
CVSS Score: 5.4
Published: 2026-10-02
A logical authorization bypass vulnerability exists in Trigger.dev versions prior to 4.5.6. This flaw allows an authenticated client with a low-trust environment API key, such as development or staging, to cancel active worker deployments in a higher-trust environment like production within the same project. The vulnerability occurs because write operations on deployments were scoped solely by project identifier instead of environment identifier.
TL;DR
An asymmetric authorization gap in Trigger.dev allows low-privilege development keys to cancel high-privilege production deployments due to a missing environment-level scoping filter on write actions.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-639
- Attack Vector: Network
- CVSS: 5.4
- Impact: Integrity and Availability (Partial)
- Exploit Status: Proof-of-Concept (PoC) available
- KEV Status: Not Listed
Affected Systems
- Trigger.dev platform self-hosted instances
- @trigger.dev/core npm package
- trigger.dev npm ecosystem
-
trigger.dev: <= 4.5.5 (Fixed in:
4.5.6)
Code Analysis
Commit: 6997aeb
Fix cross-environment deployment cancellation vulnerability by passing and validating environmentId in DeploymentService
Exploit Details
- GitHub Advisory: Analysis of cross-environment deployment cancel vulnerability
Mitigation Strategies
- Upgrade all Trigger.dev services and packages to version 4.5.6 or later.
- Rotate all environment-specific API keys, especially development and staging credentials.
- Implement monitoring to track unexpected cross-environment deployment cancellations.
Remediation Steps:
- Modify package.json to specify version ^4.5.6 for all
@trigger.dev/*modules. - Run npm install or yarn install to update the lockfile and propagate changes.
- Redeploy self-hosted application servers with the updated v4.5.6 container images.
- Access the Trigger.dev administrative dashboard to revoke and regenerate API keys for non-production environments.
References
Read the full report for GHSA-4672-HWV6-GQ62 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)