DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-4672-HWV6-GQ62: GHSA-4672-HWV6-GQ62: Cross-environment deployment cancellation in Trigger.dev

GHSA-4672-HWV6-GQ62: Cross-environment deployment cancellation in Trigger.dev

Vulnerability ID: GHSA-4672-HWV6-GQ62
CVSS Score: 5.4
Published: 2026-10-02

A logical authorization bypass vulnerability exists in Trigger.dev versions prior to 4.5.6. This flaw allows an authenticated client with a low-trust environment API key, such as development or staging, to cancel active worker deployments in a higher-trust environment like production within the same project. The vulnerability occurs because write operations on deployments were scoped solely by project identifier instead of environment identifier.

TL;DR

An asymmetric authorization gap in Trigger.dev allows low-privilege development keys to cancel high-privilege production deployments due to a missing environment-level scoping filter on write actions.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-639
  • Attack Vector: Network
  • CVSS: 5.4
  • Impact: Integrity and Availability (Partial)
  • Exploit Status: Proof-of-Concept (PoC) available
  • KEV Status: Not Listed

Affected Systems

  • Trigger.dev platform self-hosted instances
  • @trigger.dev/core npm package
  • trigger.dev npm ecosystem
  • trigger.dev: <= 4.5.5 (Fixed in: 4.5.6)

Code Analysis

Commit: 6997aeb

Fix cross-environment deployment cancellation vulnerability by passing and validating environmentId in DeploymentService

Exploit Details

  • GitHub Advisory: Analysis of cross-environment deployment cancel vulnerability

Mitigation Strategies

  • Upgrade all Trigger.dev services and packages to version 4.5.6 or later.
  • Rotate all environment-specific API keys, especially development and staging credentials.
  • Implement monitoring to track unexpected cross-environment deployment cancellations.

Remediation Steps:

  1. Modify package.json to specify version ^4.5.6 for all @trigger.dev/* modules.
  2. Run npm install or yarn install to update the lockfile and propagate changes.
  3. Redeploy self-hosted application servers with the updated v4.5.6 container images.
  4. Access the Trigger.dev administrative dashboard to revoke and regenerate API keys for non-production environments.

References


Read the full report for GHSA-4672-HWV6-GQ62 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)