CVE-2026-85650: Server-Side Request Forgery in Trigger.dev Webhook Alert Channel Delivery
Vulnerability ID: GHSA-XXV7-2VV3-H682
CVSS Score: 7.7
Published: 2026-10-02
A critical Server-Side Request Forgery (SSRF) vulnerability in Trigger.dev prior to version 4.5.2 allows authenticated organization members to configure webhook alert channels with unvalidated target URLs. This can lead to internal network scanning and cloud metadata extraction.
TL;DR
Unvalidated webhook URLs in Trigger.dev allow authenticated users to perform server-side requests against internal services and cloud metadata endpoints.
⚠️ Exploit Status: POC
Technical Details
- CWE ID: CWE-918 (Server-Side Request Forgery)
- Attack Vector: Network (AV:N)
- CVSS v3.1 Base Score: 7.7 (High)
- EPSS Score: 0.00348
- Exploit Status: PoC (Proof of Concept Available)
- KEV Status: Not Listed
Affected Systems
- Trigger.dev Control Plane Webapp
- Trigger.dev Self-Hosted Web Application
-
trigger.dev: < 4.5.2 (Fixed in:
4.5.2)
Code Analysis
Commit: 34b1a18
Fix Severe SSRF via safe Webhook fetch implementation with connection socket resolution filtering.
Exploit Details
- GitHub Security Advisory: Exploit methodology and remediation report for the webhook delivery SSRF.
Mitigation Strategies
- Implement multi-layered input schema validation to prevent local IP entry.
- Execute connection-bound socket DNS validation to prevent DNS rebinding.
- Deploy step-by-step redirect validation limited to 5 hops.
- Enforce network egress filtering to segment internal services.
Remediation Steps:
- Upgrade Trigger.dev self-hosted instances to version 4.5.2 or above.
- Verify active database entries in 'ProjectAlert' for non-public IP configurations.
- Configure firewalls to block outbound traffic from the Trigger.dev control plane to the private network range.
- Enforce IMDSv2 with a hop limit of 1 in cloud hosting environments.
References
- GitHub Advisory GHSA-xxv7-2vv3-h682
- Official Patch Commit
- Trigger.dev Release v4.5.2
- Authoritative CVE Record
Read the full report for GHSA-XXV7-2VV3-H682 on our website for more details including interactive diagrams and full exploit analysis.
Top comments (0)