DEV Community

CVE Reports
CVE Reports

Posted on Originally published at cvereports.com

GHSA-XXV7-2VV3-H682: CVE-2026-85650: Server-Side Request Forgery in Trigger.dev Webhook Alert Channel Delivery

CVE-2026-85650: Server-Side Request Forgery in Trigger.dev Webhook Alert Channel Delivery

Vulnerability ID: GHSA-XXV7-2VV3-H682
CVSS Score: 7.7
Published: 2026-10-02

A critical Server-Side Request Forgery (SSRF) vulnerability in Trigger.dev prior to version 4.5.2 allows authenticated organization members to configure webhook alert channels with unvalidated target URLs. This can lead to internal network scanning and cloud metadata extraction.

TL;DR

Unvalidated webhook URLs in Trigger.dev allow authenticated users to perform server-side requests against internal services and cloud metadata endpoints.


⚠️ Exploit Status: POC

Technical Details

  • CWE ID: CWE-918 (Server-Side Request Forgery)
  • Attack Vector: Network (AV:N)
  • CVSS v3.1 Base Score: 7.7 (High)
  • EPSS Score: 0.00348
  • Exploit Status: PoC (Proof of Concept Available)
  • KEV Status: Not Listed

Affected Systems

  • Trigger.dev Control Plane Webapp
  • Trigger.dev Self-Hosted Web Application
  • trigger.dev: < 4.5.2 (Fixed in: 4.5.2)

Code Analysis

Commit: 34b1a18

Fix Severe SSRF via safe Webhook fetch implementation with connection socket resolution filtering.

Exploit Details

Mitigation Strategies

  • Implement multi-layered input schema validation to prevent local IP entry.
  • Execute connection-bound socket DNS validation to prevent DNS rebinding.
  • Deploy step-by-step redirect validation limited to 5 hops.
  • Enforce network egress filtering to segment internal services.

Remediation Steps:

  1. Upgrade Trigger.dev self-hosted instances to version 4.5.2 or above.
  2. Verify active database entries in 'ProjectAlert' for non-public IP configurations.
  3. Configure firewalls to block outbound traffic from the Trigger.dev control plane to the private network range.
  4. Enforce IMDSv2 with a hop limit of 1 in cloud hosting environments.

References


Read the full report for GHSA-XXV7-2VV3-H682 on our website for more details including interactive diagrams and full exploit analysis.

Top comments (0)