GHSA-9Q4R-4842-93VW: Cross-Tenant SQL Injection in Trigger.dev TSQL Query Compiler
Vulnerability ID: GHSA-9Q4R-4842-93VW
CVSS Score: 7.7
Published: 2026-10-02
A critical cross-tenant SQL injection vulnerability exists in the TSQL query compiler of Trigger.dev, allowing authenticated users to bypass tenant isolation boundaries and read arbitrary ClickHouse analytics logs and execution payloads belonging to other organizations.
TL;DR
Authenticated cross-tenant SQL injection in Trigger.dev via unsanitized window-function names in the TSQL compiler allows unauthorized extraction of other organizations' data.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-89, CWE-639
- Attack Vector: Network
- CVSS Score: 7.7 (High)
- Exploit Status: Proof of Concept (PoC) available
- KEV Status: Not Listed
- Impact: Cross-tenant data exfiltration
Affected Systems
- Trigger.dev self-hosted platforms
- Trigger.dev cloud service
-
trigger.dev: <= 4.5.5 (Fixed in:
4.5.6)
Exploit Details
- GitHub Security Advisory: Contains detailed instructions and full TSQL query payload demonstrating cross-tenant exfiltration
Mitigation Strategies
- Upgrade Trigger.dev self-hosted instances to version 4.5.6 or later.
- Deploy WAF rules to detect and drop query requests containing backtick character arrays that embed standard SQL statements (SELECT, FROM, WHERE, etc.).
Remediation Steps:
- Identify all current self-hosted or managed container versions of Trigger.dev.
- Update the service dependencies and configuration to point to version 4.5.6 or a newer release.
- Verify that client libraries or API integration endpoints are calling the patched backend server.
- Optionally execute an audit over ClickHouse log histories to locate any prior exploitation attempts targeting the task_runs_v2 table containing mismatching tenant identifiers.
References
- GitHub Security Advisory GHSA-9q4r-4842-93vw
- Repository Advisory for GHSA-9q4r-4842-93vw
- Fix Pull Request #4316
- Fix Patch Commit 6997aeb05e27d2db47f9eda01fdc8a17c81a1ae0
- Release Tag v4.5.6
Read the full report for GHSA-9Q4R-4842-93VW on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)