DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-9Q4R-4842-93VW: GHSA-9Q4R-4842-93VW: Cross-Tenant SQL Injection in Trigger.dev TSQL Query Compiler

GHSA-9Q4R-4842-93VW: Cross-Tenant SQL Injection in Trigger.dev TSQL Query Compiler

Vulnerability ID: GHSA-9Q4R-4842-93VW
CVSS Score: 7.7
Published: 2026-10-02

A critical cross-tenant SQL injection vulnerability exists in the TSQL query compiler of Trigger.dev, allowing authenticated users to bypass tenant isolation boundaries and read arbitrary ClickHouse analytics logs and execution payloads belonging to other organizations.

TL;DR

Authenticated cross-tenant SQL injection in Trigger.dev via unsanitized window-function names in the TSQL compiler allows unauthorized extraction of other organizations' data.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-89, CWE-639
  • Attack Vector: Network
  • CVSS Score: 7.7 (High)
  • Exploit Status: Proof of Concept (PoC) available
  • KEV Status: Not Listed
  • Impact: Cross-tenant data exfiltration

Affected Systems

  • Trigger.dev self-hosted platforms
  • Trigger.dev cloud service
  • trigger.dev: <= 4.5.5 (Fixed in: 4.5.6)

Exploit Details

  • GitHub Security Advisory: Contains detailed instructions and full TSQL query payload demonstrating cross-tenant exfiltration

Mitigation Strategies

  • Upgrade Trigger.dev self-hosted instances to version 4.5.6 or later.
  • Deploy WAF rules to detect and drop query requests containing backtick character arrays that embed standard SQL statements (SELECT, FROM, WHERE, etc.).

Remediation Steps:

  1. Identify all current self-hosted or managed container versions of Trigger.dev.
  2. Update the service dependencies and configuration to point to version 4.5.6 or a newer release.
  3. Verify that client libraries or API integration endpoints are calling the patched backend server.
  4. Optionally execute an audit over ClickHouse log histories to locate any prior exploitation attempts targeting the task_runs_v2 table containing mismatching tenant identifiers.

References


Read the full report for GHSA-9Q4R-4842-93VW on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)