DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-FJ2X-MQQP-3V2W: GHSA-FJ2X-MQQP-3V2W: Sensitive Information Disclosure in Trigger.dev CLI Build Logs

GHSA-FJ2X-MQQP-3V2W: Sensitive Information Disclosure in Trigger.dev CLI Build Logs

Vulnerability ID: GHSA-FJ2X-MQQP-3V2W
CVSS Score: 7.5
Published: 2026-10-02

A sensitive information disclosure vulnerability exists in the Trigger.dev Command Line Interface (CLI) framework. When executing build processes inside CLI v3 packages, the framework's debug deployment logs print unredacted, resolved environment variables and secrets to standard output or log streams. This exposure occurs when the CLI is operated with a high logging verbosity level, enabling any individual or automated system with read access to build logs, CI/CD output consoles, or local development streams to capture plaintext sensitive parameters, such as database credentials, API keys, and private external integration tokens.

TL;DR

The Trigger.dev CLI v3 exposed plaintext environment variables and sensitive API keys in stdout during build deployments when debug logging was enabled. Upgrading to version v4.5.9 or later resolves the vulnerability by implementing a strict metadata-only allowlist log handler.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-532
  • Attack Vector: Local / Log Access
  • CVSS: 7.5 (High)
  • Exploit Status: Proof of Concept (Unit Tests)
  • KEV Status: Not Listed

Affected Systems

  • Trigger.dev CLI packages (@trigger.dev/cli v3)
  • @trigger.dev/cli: < 4.5.9 (Fixed in: 4.5.9)

Code Analysis

Commit: 878c158

Refactor buildWorker initialization logging to utilize structured metadata formatting instead of raw configuration parameters

Mitigation Strategies

  • Upgrade the @trigger.dev/cli package to v4.5.9 or higher.
  • Limit verbose debugging log configuration in production environments.
  • Utilize CI/CD pipeline secrets masking utilities to programmatically filter sensitive console outputs.

Remediation Steps:

  1. Navigate to the application root directory.
  2. Execute package manager command to install @trigger.dev/cli@latest.
  3. Audit active deployment pipelines and remove --log-level debug flags.
  4. Query centralized logging stores for historical logs containing 'Starting buildWorker'.
  5. Rotate any API keys, tokens, or credentials identified in legacy log entries.

References


Read the full report for GHSA-FJ2X-MQQP-3V2W on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)